๐Ÿ” CVE Alert

CVE-2026-45123

MEDIUM 4.3

MyBB: IPv6 SSRF

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in fetch_remote_file() fails open when get_ip_by_hostname() returns no result because that function does not return IPv6 results, allowing a crafted remote target to bypass the host restriction. The uniquely identifying implementation details include fail-open verification, and inc/functions.php. This issue is fixed in version 1.8.40.

CWE CWE-918
Vendor mybb
Product mybb
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for mybb mybb

Be the first to know when new medium vulnerabilities affecting mybb mybb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

mybb / mybb
< 1.8.40

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mybb/mybb/security/advisories/GHSA-56wr-64wx-5g7j github.com: https://github.com/mybb/mybb/commit/9cdadbf66f4cef50019f13aaa8e3470ea6535cb7 github.com: https://github.com/mybb/mybb/releases/tag/mybb_1840 mybb.com: https://mybb.com/versions/1.8.40