PT-2026-25381 · Kasuganosoras+1 · Pigeon

Mabjr33

+1

·

Published

2026-03-13

·

Updated

2026-03-16

·

CVE-2026-32616

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pigeon versions prior to 1.0.201
Description Pigeon is a message board/notepad/social system/blog. The application uses $ SERVER['HTTP HOST'] without validation when constructing email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in an HTTP request, causing the verification link sent to a user’s email to point to an attacker-controlled domain. This can lead to account takeover by stealing the email verification token. The vulnerable component uses the $ SERVER['HTTP HOST'] variable to construct the email verification URL.
Recommendations Update Pigeon to version 1.0.201 or later.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32616
GHSA-RRJ4-9WGQ-PRCR

Affected Products

Pigeon