CVE-2026-26747

CRITICAL

Monica 4.1.2 - Host Header Poisoning

Title source: llm
STIX 2.1

Description

A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates absolute URLs (such as those used in password reset emails) using the user-supplied Host header. This allows remote attackers to poison the password reset link sent to a victim,

Scores

CVSS v3 9.1
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-644
Status published
Products (1)
monicahq/monica 4.1.2
Published Feb 20, 2026
Tracked Since Feb 21, 2026