Perfood maintains a focused authentication product (CouchAuth) where disclosed vulnerabilities center on sensitive data handling, specifically cleartext storage of sensitive information in memory and injection-class output neutralization issues. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Perfood over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39655CRITICAL A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, i | Jan 3, 2024 | 9.6 | 26 | NO | NO |
CVE-2025-60794MEDIUM Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a windo | Nov 20, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Perfood.
Media articles that mention a CVE ID that affects a product developed by Perfood — matched by CVE ID, not by vendor name.