password-reset
Safeguard articles tagged "password-reset" — guides, analysis, and best practices for software supply chain and application security.
4 articles
Your Application's Hostname Should Not Be an Input
To build a reset link your app needs to know its own hostname, and the convenient place to find it is the Host header. That header is supplied by the client, so a stranger decides what goes in the email you send.
Account Recovery Is the Weakest Authentication You Have
You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.
GitLab Account Takeover via Password Reset (CVE-2023-7028) Explained
CVE-2023-7028 let attackers send GitLab password-reset links to an address they controlled — a zero-interaction account takeover scored 10.0. Here's the flaw and the fix.
CVE-2019-19844: Django password reset token weakness
CVE-2019-19844 let attackers hijack Django accounts by exploiting how case-sensitive email matching broke the base36 password reset token flow.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.