---
id: CVE-2026-50635
title: >-
  LimeSurvey constructs account password-reset links from the client-supplied
  HTTP Host header without validating it
summary: >-
  LimeSurvey constructs account password-reset links from the client-supplied
  HTTP Host header without validating it. The optional allowedHosts allowlist
  that would constrain this is undefined in the default (and documented)
  configuration,…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-640
vendor: LimeSurvey
product: LimeSurvey
affected:
  - LimeSurvey <= 7.0
published: '2026-06-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:19.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50635'
references:
  - url: 'https://github.com/LimeSurvey/LimeSurvey/pull/5032'
    label: disclosure@vulncheck.com
  - url: 'https://www.limesurvey.org/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/limesurvey-password-reset-host-header-injection-discloses-reset-token
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-09T18:20:43.192036Z'
epss: 0.00661
epssPercentile: 0.50063
ingestedAt: '2026-10-08T16:52:14.685Z'
---

## Overview

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
