CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-16 15:16

Updated : 2026-06-17 14:17


NVD link : CVE-2026-48780

Mitre link : CVE-2026-48780

CVE.ORG link : CVE-2026-48780


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication