
CVE-2026-32616 Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification … https://www.cve.org/CVERecord?id=CVE-2026-32616
Post summary
CVE-2026-32616 describes unsanitized use of $_SERVER['HTTP_HOST'] in Pigeon’s email verification, providing a technical vulnerability disclosure without mention of exploits or patches.
