{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27812",
        "tracking": {
            "current_release_date": "2026-03-23T01:14:21.525022Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27812",
            "initial_release_date": "2026-02-26T00:25:36.027532Z",
            "revision_history": [
                {
                    "date": "2026-02-26T00:25:36.027532Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T00:25:37.654236Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-26T00:38:31.479251Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T00:38:36.009653Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T11:47:03.312587Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (79).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T11:47:11.282984Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T14:13:33.189466Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-26T14:13:34.523513Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T15:49:07.551454Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-05T16:25:09.307524Z",
                    "number": "10",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-05T16:25:19.041181Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T18:24:54.650614Z",
                    "number": "12",
                    "summary": "Products created (1).| Product Identifiers created (1).| Products removed (1)."
                },
                {
                    "date": "2026-03-20T09:39:42.970902Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                }
            ],
            "status": "interim",
            "version": "13"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<0.1.85",
                                "product": {
                                    "name": "vers:unknown/<0.1.85",
                                    "product_id": "CSAFPID-5723109"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sub2api"
                    }
                ],
                "category": "vendor",
                "name": "Wei-Shaw"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<0.1.85",
                                "product": {
                                    "name": "vers:unknown/<0.1.85",
                                    "product_id": "CSAFPID-5763310",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:sub2api:sub2api:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sub2api"
                    }
                ],
                "category": "vendor",
                "name": "sub2api"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0",
                                "product": {
                                    "name": "vers:unknown/v0.1.0",
                                    "product_id": "CSAFPID-5729688"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.1",
                                "product": {
                                    "name": "vers:unknown/v0.1.1",
                                    "product_id": "CSAFPID-5729689"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.10",
                                "product": {
                                    "name": "vers:unknown/v0.1.10",
                                    "product_id": "CSAFPID-5729690"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.11",
                                "product": {
                                    "name": "vers:unknown/v0.1.11",
                                    "product_id": "CSAFPID-5729691"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.12",
                                "product": {
                                    "name": "vers:unknown/v0.1.12",
                                    "product_id": "CSAFPID-5729692"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.13",
                                "product": {
                                    "name": "vers:unknown/v0.1.13",
                                    "product_id": "CSAFPID-5729693"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.14",
                                "product": {
                                    "name": "vers:unknown/v0.1.14",
                                    "product_id": "CSAFPID-5729694"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.15",
                                "product": {
                                    "name": "vers:unknown/v0.1.15",
                                    "product_id": "CSAFPID-5729695"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.16",
                                "product": {
                                    "name": "vers:unknown/v0.1.16",
                                    "product_id": "CSAFPID-5729696"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.17",
                                "product": {
                                    "name": "vers:unknown/v0.1.17",
                                    "product_id": "CSAFPID-5729697"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.18",
                                "product": {
                                    "name": "vers:unknown/v0.1.18",
                                    "product_id": "CSAFPID-5729698"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.19",
                                "product": {
                                    "name": "vers:unknown/v0.1.19",
                                    "product_id": "CSAFPID-5729699"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.2",
                                "product": {
                                    "name": "vers:unknown/v0.1.2",
                                    "product_id": "CSAFPID-5729700"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.20",
                                "product": {
                                    "name": "vers:unknown/v0.1.20",
                                    "product_id": "CSAFPID-5729701"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.21",
                                "product": {
                                    "name": "vers:unknown/v0.1.21",
                                    "product_id": "CSAFPID-5729702"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.22",
                                "product": {
                                    "name": "vers:unknown/v0.1.22",
                                    "product_id": "CSAFPID-5729703"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.23",
                                "product": {
                                    "name": "vers:unknown/v0.1.23",
                                    "product_id": "CSAFPID-5729704"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.24",
                                "product": {
                                    "name": "vers:unknown/v0.1.24",
                                    "product_id": "CSAFPID-5729705"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.25",
                                "product": {
                                    "name": "vers:unknown/v0.1.25",
                                    "product_id": "CSAFPID-5729706"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.26",
                                "product": {
                                    "name": "vers:unknown/v0.1.26",
                                    "product_id": "CSAFPID-5729707"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.27",
                                "product": {
                                    "name": "vers:unknown/v0.1.27",
                                    "product_id": "CSAFPID-5729708"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.28",
                                "product": {
                                    "name": "vers:unknown/v0.1.28",
                                    "product_id": "CSAFPID-5729709"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.29",
                                "product": {
                                    "name": "vers:unknown/v0.1.29",
                                    "product_id": "CSAFPID-5729710"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.3",
                                "product": {
                                    "name": "vers:unknown/v0.1.3",
                                    "product_id": "CSAFPID-5729711"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.30",
                                "product": {
                                    "name": "vers:unknown/v0.1.30",
                                    "product_id": "CSAFPID-5729712"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.31",
                                "product": {
                                    "name": "vers:unknown/v0.1.31",
                                    "product_id": "CSAFPID-5729713"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.32",
                                "product": {
                                    "name": "vers:unknown/v0.1.32",
                                    "product_id": "CSAFPID-5729714"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.33",
                                "product": {
                                    "name": "vers:unknown/v0.1.33",
                                    "product_id": "CSAFPID-5729715"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.34",
                                "product": {
                                    "name": "vers:unknown/v0.1.34",
                                    "product_id": "CSAFPID-5729716"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.35",
                                "product": {
                                    "name": "vers:unknown/v0.1.35",
                                    "product_id": "CSAFPID-5729717"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.38",
                                "product": {
                                    "name": "vers:unknown/v0.1.38",
                                    "product_id": "CSAFPID-5729718"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.39",
                                "product": {
                                    "name": "vers:unknown/v0.1.39",
                                    "product_id": "CSAFPID-5729719"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.4",
                                "product": {
                                    "name": "vers:unknown/v0.1.4",
                                    "product_id": "CSAFPID-5729720"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.40",
                                "product": {
                                    "name": "vers:unknown/v0.1.40",
                                    "product_id": "CSAFPID-5729721"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.41",
                                "product": {
                                    "name": "vers:unknown/v0.1.41",
                                    "product_id": "CSAFPID-5729722"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.42",
                                "product": {
                                    "name": "vers:unknown/v0.1.42",
                                    "product_id": "CSAFPID-5729723"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.43",
                                "product": {
                                    "name": "vers:unknown/v0.1.43",
                                    "product_id": "CSAFPID-5729724"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.44",
                                "product": {
                                    "name": "vers:unknown/v0.1.44",
                                    "product_id": "CSAFPID-5729725"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.45",
                                "product": {
                                    "name": "vers:unknown/v0.1.45",
                                    "product_id": "CSAFPID-5729726"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.46",
                                "product": {
                                    "name": "vers:unknown/v0.1.46",
                                    "product_id": "CSAFPID-5729727"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.47",
                                "product": {
                                    "name": "vers:unknown/v0.1.47",
                                    "product_id": "CSAFPID-5729728"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.48",
                                "product": {
                                    "name": "vers:unknown/v0.1.48",
                                    "product_id": "CSAFPID-5729729"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.49",
                                "product": {
                                    "name": "vers:unknown/v0.1.49",
                                    "product_id": "CSAFPID-5729730"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.5",
                                "product": {
                                    "name": "vers:unknown/v0.1.5",
                                    "product_id": "CSAFPID-5729731"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.50",
                                "product": {
                                    "name": "vers:unknown/v0.1.50",
                                    "product_id": "CSAFPID-5729732"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.51",
                                "product": {
                                    "name": "vers:unknown/v0.1.51",
                                    "product_id": "CSAFPID-5729733"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.52",
                                "product": {
                                    "name": "vers:unknown/v0.1.52",
                                    "product_id": "CSAFPID-5729734"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.53",
                                "product": {
                                    "name": "vers:unknown/v0.1.53",
                                    "product_id": "CSAFPID-5729735"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.55",
                                "product": {
                                    "name": "vers:unknown/v0.1.55",
                                    "product_id": "CSAFPID-5729736"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.56",
                                "product": {
                                    "name": "vers:unknown/v0.1.56",
                                    "product_id": "CSAFPID-5729737"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.57",
                                "product": {
                                    "name": "vers:unknown/v0.1.57",
                                    "product_id": "CSAFPID-5729738"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.58",
                                "product": {
                                    "name": "vers:unknown/v0.1.58",
                                    "product_id": "CSAFPID-5729739"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.59",
                                "product": {
                                    "name": "vers:unknown/v0.1.59",
                                    "product_id": "CSAFPID-5729740"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.6",
                                "product": {
                                    "name": "vers:unknown/v0.1.6",
                                    "product_id": "CSAFPID-5729741"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.60",
                                "product": {
                                    "name": "vers:unknown/v0.1.60",
                                    "product_id": "CSAFPID-5729742"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.61",
                                "product": {
                                    "name": "vers:unknown/v0.1.61",
                                    "product_id": "CSAFPID-5729743"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.62",
                                "product": {
                                    "name": "vers:unknown/v0.1.62",
                                    "product_id": "CSAFPID-5729744"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.63",
                                "product": {
                                    "name": "vers:unknown/v0.1.63",
                                    "product_id": "CSAFPID-5729745"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.64",
                                "product": {
                                    "name": "vers:unknown/v0.1.64",
                                    "product_id": "CSAFPID-5729746"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.65",
                                "product": {
                                    "name": "vers:unknown/v0.1.65",
                                    "product_id": "CSAFPID-5729747"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.66",
                                "product": {
                                    "name": "vers:unknown/v0.1.66",
                                    "product_id": "CSAFPID-5729748"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.69",
                                "product": {
                                    "name": "vers:unknown/v0.1.69",
                                    "product_id": "CSAFPID-5729749"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.7",
                                "product": {
                                    "name": "vers:unknown/v0.1.7",
                                    "product_id": "CSAFPID-5729750"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.70",
                                "product": {
                                    "name": "vers:unknown/v0.1.70",
                                    "product_id": "CSAFPID-5729751"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.71",
                                "product": {
                                    "name": "vers:unknown/v0.1.71",
                                    "product_id": "CSAFPID-5729752"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.72",
                                "product": {
                                    "name": "vers:unknown/v0.1.72",
                                    "product_id": "CSAFPID-5729753"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.73",
                                "product": {
                                    "name": "vers:unknown/v0.1.73",
                                    "product_id": "CSAFPID-5729754"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.74",
                                "product": {
                                    "name": "vers:unknown/v0.1.74",
                                    "product_id": "CSAFPID-5729755"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.75",
                                "product": {
                                    "name": "vers:unknown/v0.1.75",
                                    "product_id": "CSAFPID-5729756"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.77",
                                "product": {
                                    "name": "vers:unknown/v0.1.77",
                                    "product_id": "CSAFPID-5729757"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.78",
                                "product": {
                                    "name": "vers:unknown/v0.1.78",
                                    "product_id": "CSAFPID-5729758"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.79",
                                "product": {
                                    "name": "vers:unknown/v0.1.79",
                                    "product_id": "CSAFPID-5729759"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.8",
                                "product": {
                                    "name": "vers:unknown/v0.1.8",
                                    "product_id": "CSAFPID-5729760"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.80",
                                "product": {
                                    "name": "vers:unknown/v0.1.80",
                                    "product_id": "CSAFPID-5729761"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.81",
                                "product": {
                                    "name": "vers:unknown/v0.1.81",
                                    "product_id": "CSAFPID-5729762"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.82",
                                "product": {
                                    "name": "vers:unknown/v0.1.82",
                                    "product_id": "CSAFPID-5729763"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.83",
                                "product": {
                                    "name": "vers:unknown/v0.1.83",
                                    "product_id": "CSAFPID-5729764"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.84",
                                "product": {
                                    "name": "vers:unknown/v0.1.84",
                                    "product_id": "CSAFPID-5729765"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.9",
                                "product": {
                                    "name": "vers:unknown/v0.1.9",
                                    "product_id": "CSAFPID-5729766"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sub2api"
                    }
                ],
                "category": "vendor",
                "name": "wei-shaw"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27812",
            "cwe": {
                "id": "CWE-116",
                "name": "Improper Encoding or Escaping of Output"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior to 0.1.85 is a Password Reset Poisoning (Host Header / Forwarded Header trust issue), which allows attackers to manipulate the password reset link. Attackers can exploit this flaw to inject their own domain into the password reset link, leading to the potential for account takeover. The vulnerability has been fixed in version v0.1.85. If upgrading is not immediately possible, users can mitigate the vulnerability by disabling the \"forgot password\" feature until an upgrade to a patched version can be performed. This will prevent attackers from exploiting the vulnerability via the affected endpoint.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-27812"
                },
                {
                    "category": "description",
                    "text": "Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior to 0.1.85 is a Password Reset Poisoning (Host Header / Forwarded Header trust issue), which allows attackers to manipulate the password reset link. Attackers can exploit this flaw to inject their own domain into the password reset link, leading to the potential for account takeover. The vulnerability has been fixed in version v0.1.85. If upgrading is not immediately possible, users can mitigate the vulnerability by disabling the \"forgot password\" feature until an upgrade to a patched version can be performed. This will prevent attackers from exploiting the vulnerability via the affected endpoint.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-27812"
                },
                {
                    "category": "description",
                    "text": "Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior to 0.1.85 is a Password Reset Poisoning (Host Header / Forwarded Header trust issue), which allows attackers to manipulate the password reset link. Attackers can exploit this flaw to inject their own domain into the password reset link, leading to the potential for account takeover. The vulnerability has been fixed in version v0.1.85. If upgrading is not immediately possible, users can mitigate the vulnerability by disabling the \"forgot password\" feature until an upgrade to a patched version can be performed. This will prevent attackers from exploiting the vulnerability via the affected endpoint.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27812.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00045",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.0",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.4",
                    "title": "NCSC Score"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5723109",
                    "CSAFPID-5729688",
                    "CSAFPID-5729689",
                    "CSAFPID-5729690",
                    "CSAFPID-5729691",
                    "CSAFPID-5729692",
                    "CSAFPID-5729693",
                    "CSAFPID-5729694",
                    "CSAFPID-5729695",
                    "CSAFPID-5729696",
                    "CSAFPID-5729697",
                    "CSAFPID-5729698",
                    "CSAFPID-5729699",
                    "CSAFPID-5729700",
                    "CSAFPID-5729701",
                    "CSAFPID-5729702",
                    "CSAFPID-5729703",
                    "CSAFPID-5729704",
                    "CSAFPID-5729705",
                    "CSAFPID-5729706",
                    "CSAFPID-5729707",
                    "CSAFPID-5729708",
                    "CSAFPID-5729709",
                    "CSAFPID-5729710",
                    "CSAFPID-5729711",
                    "CSAFPID-5729712",
                    "CSAFPID-5729713",
                    "CSAFPID-5729714",
                    "CSAFPID-5729715",
                    "CSAFPID-5729716",
                    "CSAFPID-5729717",
                    "CSAFPID-5729718",
                    "CSAFPID-5729719",
                    "CSAFPID-5729720",
                    "CSAFPID-5729721",
                    "CSAFPID-5729722",
                    "CSAFPID-5729723",
                    "CSAFPID-5729724",
                    "CSAFPID-5729725",
                    "CSAFPID-5729726",
                    "CSAFPID-5729727",
                    "CSAFPID-5729728",
                    "CSAFPID-5729729",
                    "CSAFPID-5729730",
                    "CSAFPID-5729731",
                    "CSAFPID-5729732",
                    "CSAFPID-5729733",
                    "CSAFPID-5729734",
                    "CSAFPID-5729735",
                    "CSAFPID-5729736",
                    "CSAFPID-5729737",
                    "CSAFPID-5729738",
                    "CSAFPID-5729739",
                    "CSAFPID-5729740",
                    "CSAFPID-5729741",
                    "CSAFPID-5729742",
                    "CSAFPID-5729743",
                    "CSAFPID-5729744",
                    "CSAFPID-5729745",
                    "CSAFPID-5729746",
                    "CSAFPID-5729747",
                    "CSAFPID-5729748",
                    "CSAFPID-5729749",
                    "CSAFPID-5729750",
                    "CSAFPID-5729751",
                    "CSAFPID-5729752",
                    "CSAFPID-5729753",
                    "CSAFPID-5729754",
                    "CSAFPID-5729755",
                    "CSAFPID-5729756",
                    "CSAFPID-5729757",
                    "CSAFPID-5729758",
                    "CSAFPID-5729759",
                    "CSAFPID-5729760",
                    "CSAFPID-5729761",
                    "CSAFPID-5729762",
                    "CSAFPID-5729763",
                    "CSAFPID-5729764",
                    "CSAFPID-5729765",
                    "CSAFPID-5729766",
                    "CSAFPID-5763310"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27812"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27812"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27812"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27812.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27812.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-27812"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/Wei-Shaw/sub2api/security/advisories/GHSA-vc2q-289v-74g3"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27812.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-5723109",
                        "CSAFPID-5729688",
                        "CSAFPID-5729689",
                        "CSAFPID-5729690",
                        "CSAFPID-5729691",
                        "CSAFPID-5729692",
                        "CSAFPID-5729693",
                        "CSAFPID-5729694",
                        "CSAFPID-5729695",
                        "CSAFPID-5729696",
                        "CSAFPID-5729697",
                        "CSAFPID-5729698",
                        "CSAFPID-5729699",
                        "CSAFPID-5729700",
                        "CSAFPID-5729701",
                        "CSAFPID-5729702",
                        "CSAFPID-5729703",
                        "CSAFPID-5729704",
                        "CSAFPID-5729705",
                        "CSAFPID-5729706",
                        "CSAFPID-5729707",
                        "CSAFPID-5729708",
                        "CSAFPID-5729709",
                        "CSAFPID-5729710",
                        "CSAFPID-5729711",
                        "CSAFPID-5729712",
                        "CSAFPID-5729713",
                        "CSAFPID-5729714",
                        "CSAFPID-5729715",
                        "CSAFPID-5729716",
                        "CSAFPID-5729717",
                        "CSAFPID-5729718",
                        "CSAFPID-5729719",
                        "CSAFPID-5729720",
                        "CSAFPID-5729721",
                        "CSAFPID-5729722",
                        "CSAFPID-5729723",
                        "CSAFPID-5729724",
                        "CSAFPID-5729725",
                        "CSAFPID-5729726",
                        "CSAFPID-5729727",
                        "CSAFPID-5729728",
                        "CSAFPID-5729729",
                        "CSAFPID-5729730",
                        "CSAFPID-5729731",
                        "CSAFPID-5729732",
                        "CSAFPID-5729733",
                        "CSAFPID-5729734",
                        "CSAFPID-5729735",
                        "CSAFPID-5729736",
                        "CSAFPID-5729737",
                        "CSAFPID-5729738",
                        "CSAFPID-5729739",
                        "CSAFPID-5729740",
                        "CSAFPID-5729741",
                        "CSAFPID-5729742",
                        "CSAFPID-5729743",
                        "CSAFPID-5729744",
                        "CSAFPID-5729745",
                        "CSAFPID-5729746",
                        "CSAFPID-5729747",
                        "CSAFPID-5729748",
                        "CSAFPID-5729749",
                        "CSAFPID-5729750",
                        "CSAFPID-5729751",
                        "CSAFPID-5729752",
                        "CSAFPID-5729753",
                        "CSAFPID-5729754",
                        "CSAFPID-5729755",
                        "CSAFPID-5729756",
                        "CSAFPID-5729757",
                        "CSAFPID-5729758",
                        "CSAFPID-5729759",
                        "CSAFPID-5729760",
                        "CSAFPID-5729761",
                        "CSAFPID-5729762",
                        "CSAFPID-5729763",
                        "CSAFPID-5729764",
                        "CSAFPID-5729765",
                        "CSAFPID-5729766",
                        "CSAFPID-5763310"
                    ]
                }
            ],
            "title": "CVE-2026-27812"
        }
    ]
}