๐Ÿ” CVE Alert

CVE-2026-29199

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover.

CWE CWE-640
Vendor phpbb
Product phpbb
Published May 4, 2026
Stay Ahead of the Next One

Get instant alerts for phpbb phpbb

Be the first to know when new unknown vulnerabilities affecting phpbb phpbb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

phpBB / phpBB
3.0.0 โ‰ค 3.3.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackerone.com: https://hackerone.com/reports/3543246

Credits

๐Ÿ” SEONG HUN JEONG (HunSec)