
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28681 is an HTTP Host header injection vulnerability in the IRRD (Internet Routing Registry Daemon) web UI that enables password reset poisoning, allowing unauthenticated attackers to redirect confirmation email links to attacker-controlled domains and take over user accounts. It affects IRRD versions 4.4.0 through 4.4.4 and version 4.5.0; IRRD 4.3 and earlier are not affected as they did not include the web UI. The vulnerability was published on March 4, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, IRRD Security Advisory).
The root cause is that email links generated during account creation, password reset, and mntner migration workflows were constructed directly from the HTTP request context without validating the Host header against the configured server.http.url value, classified as CWE-601 (URL Redirection to Untrusted Site) and CWE-640 (Weak Password Recovery Mechanism). An unauthenticated attacker can send a password reset or account creation request to the IRRD web UI with a spoofed Host header pointing to an attacker-controlled domain; the resulting confirmation email sent to the victim will contain a link to the attacker's domain rather than the legitimate IRRD instance. When the victim clicks the link, the password reset token is transmitted to the attacker's server, who can then replay it against the real IRRD instance to complete the account takeover. No prior authentication or special privileges are required — only the ability to send an HTTP request with a manipulated Host header (GitHub Advisory, IRRD Security Advisory).
A successful exploit results in full account takeover of the targeted IRRD user, granting the attacker the ability to modify RPSL (Routing Policy Specification Language) objects maintained by the account's mntners, which can have significant consequences for Internet routing integrity. Confidentiality and integrity impacts are both rated High, as the attacker gains access to account credentials and can alter authoritative routing registry data. Availability is not directly impacted. Accounts protected by two-factor authentication (2FA) — required for users with override access — cannot be fully compromised even if the password reset token is stolen, providing a secondary protection layer for high-privilege accounts (GitHub Advisory, IRRD Security Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039% (12th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
/ui/password-reset/) with a spoofed Host header set to an attacker-controlled domain (e.g., Host: attacker.com).Host header value — e.g., https://attacker.com/ui/password-reset/confirm/?token=<TOKEN>.token parameter from the URL.Host header value that does not match the configured server.http.url (these would be blocked after patching but may appear in pre-patch logs).Upgrade IRRD to version 4.4.5 (for the 4.4.x branch) or 4.5.1 (for the 4.5.x branch), which add TrustedHostMiddleware to reject requests where the Host header does not match the configured server.http.url, and invalidate all existing password reset tokens to neutralize any previously captured tokens. As an interim workaround, configure a reverse proxy (e.g., nginx) to reject requests with a Host header that does not match the expected hostname. Additionally, enabling two-factor authentication for all users — especially those with override access — is strongly recommended, as 2FA prevents account takeover even if a reset token is compromised (GitHub Advisory, IRRD Security Advisory).
The vulnerability was reported by researcher BrookeYangRui and published by IRRD maintainer mxsasha on March 4, 2026. The advisory received coverage from automated security feeds and community aggregators including Mastodon security accounts and Bluesky CVE trackers shortly after disclosure. No major vendor statements beyond the IRRD project's own advisory or significant independent researcher commentary have been identified (IRRD Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."