CVE-2026-45123: MyBB: IPv6 SSRF

Published Aug 18, 2026
·
Updated

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in fetchremotefile() fails open when getipbyhostname() returns no result because that function does not return IPv6 results, allowing a crafted remote target to bypass the host restriction. The uniquely identifying implementation details include fail-open verification, and inc/functions.php. This issue is fixed in version 1.8.40.

Affected Software

1 affected component
MyBB MyBB<1.8.40

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MyBB to a version that resolves this vulnerability.

    Fixed in 1.8.40

Event History

Aug 18, 2026
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Instances running MyBB before 1.8.40 are affected when the remote requests feature can be induced to fetch an attacker-crafted target. The default disallowed remote-host list does not cover IPv6 addresses.

2

What does an attacker need to exploit this issue?

An attacker needs privileges to use a feature or workflow that triggers MyBB remote requests; no user interaction is required. They can use a crafted IPv6 target to bypass host restrictions because hostname resolution does not return IPv6 results and the verification fails open.

3

What should administrators do if they cannot patch immediately?

Upgrade MyBB to version 1.8.40. If upgrading cannot happen immediately, restrict or disable access to functionality that can trigger remote requests, particularly for lower-privileged users, and prevent the application host from reaching sensitive internal and IPv6 network destinations.

4

How can I determine whether my instance is affected?

Review the installed MyBB version and treat versions earlier than 1.8.40 as affected. Also inspect uses of fetch_remote_file() and any remote-request functionality for requests to IPv6 literals or IPv6-resolving hostnames that bypass intended host restrictions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203