Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows. | |
| Title | Grav before 3.9.2 Host Header Injection via sendInvitationEmail | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-350 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:10.057Z
Reserved: 2026-06-22T18:48:27.060Z
Link: CVE-2026-56709
No data.
Status : Received
Published: 2026-08-25T02:16:42.930
Modified: 2026-08-25T02:16:42.930
Link: CVE-2026-56709
No data.
OpenCVE Enrichment
No data.