Description
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows. | |
| Title | Grav before 3.9.2 Host Header Injection via sendInvitationEmail | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-350 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:10.057Z
Reserved: 2026-06-22T18:48:27.060Z
Link: CVE-2026-56709
No data.
Status : Received
Published: 2026-08-25T02:16:42.930
Modified: 2026-08-25T02:16:42.930
Link: CVE-2026-56709
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action