8.2
CVE-2026-48780
- EPSS 0.22%
- Veröffentlicht 16.06.2026 14:10:27
- Zuletzt bearbeitet 16.06.2026 15:46:16
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Forem vulnerable to bypass of email address domain restrictions
Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerforem
≫
Produkt
forem
Version
< a2ab6d4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.12 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://github.com/forem/forem/security/advisories/GHSA-3g4h-9h37-mpx6
https://github.com/forem/forem/commit/a2ab6d409d2676eb0711ecbd737192043125b437