CVE-2026-29199Disclosure(phpbb / phpbb)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch phpbb phpbb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • phpbb

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
phpbb

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-16: 1Mentions · 2026-05-29: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-16: 1Technical Details · 2026-05-29: 105-0405-1605-29
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-161
Disclosure1
2026-05-291
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 #phpBB, Host Header Injection, #CVE-2026-29199 (High) -DC-May2026-43 https://dailycve.com/phpbb-host-header-injection-cve-2026-29199-high-dc-may2026-43/

    Post summary

    A high‑severity Host Header Injection vulnerability (CVE‑2026‑29199) in PHPBB is disclosed with basic technical details.

    0000040
    207 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A high-severity vulnerability (CVE-2026-29199) affects phpBB versions before 3.3.16, allowing Host Header Injection to poison password reset links. If you use phpBB, update promptly and review your server’s host header validation to protect accounts. #cybersecurity

    Post summary

    CVE-2026-29199 is a high‑severity host header injection flaw in phpBB versions prior to 3.3.16, enabling malicious password reset links; users are urged to update to the latest version to mitigate.

    0000048
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29199 Host Header Injection in phpBB Before 3.3.16 Leading to Password Reset Link Poisoning https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29199

    Post summary

    The post announces a Host Header Injection flaw in phpBB versions prior to 3.3.16 that can be abused to poison password reset links. No PoC, exploit code, or remediation details are provided.

    0000061
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29199 phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may… https://www.cve.org/CVERecord?id=CVE-2026-29199

    Post summary

    CVE-2026-29199 describes a Host Header Injection vulnerability in phpBB versions prior to 3.3.16 that can lead to password reset link poisoning when force_server_vars is disabled. No PoC, exploit code, or active exploitation details are provided in the text.

    00000139
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpbbphpbb---

Explore more