CVE-2026-29199
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover.
| CWE | CWE-640 |
| Vendor | phpbb |
| Product | phpbb |
| Published | May 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for phpbb phpbb
Be the first to know when new unknown vulnerabilities affecting phpbb phpbb are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
phpBB / phpBB
3.0.0 โค 3.3.15
Credits
๐ SEONG HUN JEONG (HunSec)