Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@perfood/couch-auth — 5 CVEs · VulnScope
pkg:npm/
@perfood/couch-auth
5 total CVEs
CRITICAL
1
HIGH
2
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.3
CVE-2025-70948
@perfood/couch-auth has a host header injection vulnerability
from 0, <= 0.26.0
HIGH
8.1
CVE-2023-39655
CouchAuth host header injection vulnerability leaks the password reset token
from 0, <= 0.20.0
HIGH
7.5
CVE-2025-70949
@perfood/couch-auth has an Observable Timing Discrepancy
from 0, <= 0.26.0
MEDIUM
4.3
CouchAuth has a Server-Side Template Injection vulnerability in its email functionality
from 0, <= 0.21.2
—
@perfood/couch-auth may expose session tokens, passwords
from 0, <= 0.21.2
CVE-2024-57177
CVE-2025-60794