CVE-2026-29199: High severity phpBB phpbb vulnerability
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When forceservervars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29199?
CVE-2026-29199 is classified as a medium severity vulnerability due to its potential for password reset link poisoning.
How do I fix CVE-2026-29199?
To fix CVE-2026-29199, upgrade phpBB to version 3.3.16 or later where the vulnerability is patched.
What can an attacker do with CVE-2026-29199?
An attacker can exploit CVE-2026-29199 to create malicious password reset links that could mislead users into providing sensitive information.
Is the Host Header Injection in CVE-2026-29199 serious?
Yes, Host Header Injection vulnerabilities like CVE-2026-29199 are serious as they can lead to serious security issues like phishing attacks.
Which versions of phpBB are affected by CVE-2026-29199?
CVE-2026-29199 affects phpBB versions prior to 3.3.16.