Skip to content

Fix possible mail header injection attack by not using HTTP_HOST#959

Merged
onli merged 3 commits intomasterfrom
fix/emailHostInjection
Apr 8, 2026
Merged

Fix possible mail header injection attack by not using HTTP_HOST#959
onli merged 3 commits intomasterfrom
fix/emailHostInjection

Conversation

@onli
Copy link
Copy Markdown
Member

@onli onli commented Apr 6, 2026

Rely on the configured $serendipity['baseURL'] instead, with additional safeguards for the baseURL autodection mode.

This is a security fix.

Rely on the configured $serendipity['baseURL'] instead, with additional safeguards for the baseURL autodection mode
@onli onli requested a review from mattsches April 6, 2026 08:11
@onli onli merged commit 20acbc2 into master Apr 8, 2026
5 checks passed
@onli onli deleted the fix/emailHostInjection branch April 8, 2026 08:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants