A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords and take over their accounts.
CVE-2023-39655
CRITICALNVD 9.69.6—
EchelonGraph scoreMEDIUM confidence
This critical-severity CVE scores 9.6 under NVD CVSS v3. EPSS exploit probability: 0.5%, top 59% of all CVEs by exploit prediction. GitHub Security Advisory enrichment pending alignment with NVD CVSS.
Triggered by: NVD CVSS baseline
Sources: epss, ghsa, nvd
9.6
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
- High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 1%CVSS: 9.6Exploit: NoneExposed: 0
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.6
- EG Score
- 9.6(medium)
- EPSS
- 41.1%
- KEV
- Not listed
Published
January 3, 2024
Last Modified
June 18, 2025
Advisory Details (1)
Auto-updated Jul 13, 2026No patch confirmed yet.
generic
vulnerability-research/CVE-2023-39655 at main · dub-flow/vulnerability-research · GitHub
https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-39655Affected Packages
(1 across 1 ecosystem)
npm(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| @perfood/couch-auth | — | — | — |
Frequently asked(5)
What is CVE-2023-39655?
CVE-2023-39655 is a critical vulnerability published on January 3, 2024. A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus…
When was CVE-2023-39655 disclosed?
CVE-2023-39655 was first published in the National Vulnerability Database on January 3, 2024, with the most recent update on June 18, 2025. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2023-39655 actively exploited?
CVE-2023-39655 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 41.1% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2023-39655?
CVE-2023-39655 has a CVSS v3 base score of 9.6 (NVD).
How do I remediate CVE-2023-39655?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2023-39655, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-39655
Is Your Infrastructure Affected by CVE-2023-39655?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.