<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T14:13:55.810339+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291461</id>
    <title>EUVD-2026-291461</title>
    <updated>2026-10-06T14:13:55.895980+00:00</updated>
    <content>EUVD-2026-291461</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39971</id>
    <title>fkie_cve-2026-39971</title>
    <updated>2026-10-06T14:13:55.896018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER['HTTP_HOST'] directly into the Message-ID SMTP header without validation, and the existing sanitization function serendipity_isResponseClean() is not called on HTTP_HOST before embedding it. An attacker who can control the Host header during an email-triggering action such as comment notifications or subscription emails can inject arbitrary SMTP headers into outgoing emails. This enables identity spoofing, reply hijacking via manipulated Message-ID threading, and email reputation abuse through the attacker's domain being embedded in legitimate mail headers. This issue has been fixed in version 2.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-458g-q4fh-mj6r</id>
    <title>GHSA-458g-q4fh-mj6r — Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email head…</title>
    <updated>2026-10-06T14:13:55.896056+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: s9y/serendipity</p>
<p>### Summary
Serendipity inserts `$_SERVER['HTTP_HOST']` directly into the `Message-ID` SMTP header without any validation beyond CRLF stripping. An attacker who can control the `Host` header during an email-triggering action can inject arbitrary SMTP headers into outgoing emails, enabling spam relay, BCC injection, and email spoofing.</p>
<p>### Details
In `include/functions.inc.php:548`:
```php
$maildata['headers'][] = 'Message-ID: &lt;' 
    . bin2hex(random_bytes(16)) 
    . '@' . $_SERVER['HTTP_HOST']  // ← unsanitized, attacker-controlled
    . '&gt;';
```</p>
<p>The existing sanitization function only blocks `\r\n` and URL-encoded variants:
```php
function serendipity_isResponseClean($d) {
    return (strpos($d, "\r") === false &amp;&amp; strpos($d, "\n") === false 
        &amp;&amp; stripos($d, "%0A") === false &amp;&amp; stripos($d, "%0D") === false);
}
```</p>
<p>Critically, `serendipity_isResponseClean()` is **not even called** on `HTTP_HOST` before embedding it into the mail headers — making this exploitable with any character that SMTP interprets as a header delimiter.</p>
<p>Email is triggered by actions such as:
- New comment notifications to blog owner
- Comment subscription notifications to subscribers
- Password reset emails (if configured)</p>
<p>### PoC
```bash
# Trigger comment notification email with injected header
curl -s -X POST \
  -H "Host: attacker.com&gt;\r\nBcc: victim@evil.com\r\nX-Injected:" \
  -d "serendipity[comment]=test&amp;serendipity[name]=hacker&amp;serendipity[email]=a@b.com&amp;serendipity[entry_id]=1" \…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-458g-q4fh-mj6r"/>
  </entry>
</feed>
