Ad

CVE-2026-32616

HIGH CVSS 3.1: 8.2 EPSS 0.04%
Updated Apr 16, 2026
Pigeon
Parameter Value
CVSS 8.2 (HIGH)
Fixed In 1.0.201
Type CWE-74 (Injection)
Vendor Pigeon
Public PoC No

Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in the HTTP request, causing the verification link sent to the user's email to point to an attacker-controlled domain.

This can lead to account takeover by stealing the email verification token. This vulnerability is fixed in 1.0.201.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)