{"id":"GHSA-4m6c-649p-f6gf","summary":"Serendipity has a Host Header Injection allows authentication cookie scoping to attacker-controlled domain in functions_config.inc.php","details":"### Summary\nThe `serendipity_setCookie()` function uses `$_SERVER['HTTP_HOST']` without validation as the `domain` parameter of `setcookie()`. An attacker can force authentication cookies — including session tokens and auto-login tokens — to be scoped to an attacker-controlled domain, facilitating session hijacking.\n\n### Details\nIn `include/functions_config.inc.php:726`:\n```php\nfunction serendipity_setCookie($name, $value, $securebyprot = true, ...) {\n    $host = $_SERVER['HTTP_HOST']; // ← attacker-controlled, no validation\n\n    if ($securebyprot) {\n        if ($pos = strpos($host, \":\")) {\n            $host = substr($host, 0, $pos); // strips port only\n        }\n    }\n\n    setcookie(\"serendipity[$name]\", $value, [\n        'domain'   =\u003e $host,   // ← poisoned domain\n        'httponly' =\u003e $httpOnly,\n        'samesite' =\u003e 'Strict'\n    ]);\n}\n```\n\nThis function is called during login with sensitive cookies:\n```php\n// functions_config.inc.php:455-498\nserendipity_setCookie('author_autologintoken', $rnd, true, false, true);\nserendipity_setCookie('author_username', $user);\nserendipity_setCookie('author_token', $hash);\n```\n\nIf an attacker can influence the `Host` header at login time (e.g. via MITM, reverse proxy misconfiguration, or load balancer), authentication cookies are issued scoped to the attacker's domain instead of the legitimate one.\n\n### PoC\n```bash\ncurl -v -X POST \\\n  -H \"Host: attacker.com\" \\\n  -d \"serendipity[user]=admin&serendipity[pass]=admin\" \\\n  http://[TARGET]/serendipity_admin.php 2\u003e&1 | grep -i \"set-cookie\"\n```\n\nExpected output:\n```http\nSet-Cookie: serendipity[author_token]=; domain=attacker.com; HttpOnly\n```\n\n### Impact\n- **Session fixation** — attacker pre-sets a cookie scoped to their domain, then tricks the victim into authenticating, inheriting the poisoned token\n- **Token leakage** — `author_autologintoken` scoped to wrong domain may be sent to attacker-controlled infrastructure\n- **Privilege escalation** — if admin logs in under a poisoned Host header, their admin token is compromised\n\n### Suggested Fix\nValidate `HTTP_HOST` against the configured `$serendipity['url']` before use:\n```php\nfunction serendipity_setCookie($name, $value, ...) {\n    global $serendipity;\n    $configured = parse_url($serendipity['url'], PHP_URL_HOST);\n    $host = preg_replace('/:[0-9]+$/', '', $_SERVER['HTTP_HOST']);\n    $host = ($host === $configured) ? $host : $configured;\n\n    setcookie(\"serendipity[$name]\", $value, [\n        'domain' =\u003e $host,\n        ...\n    ]);\n}\n```","aliases":["CVE-2026-39963"],"modified":"2026-04-15T21:35:53.816830Z","published":"2026-04-14T22:32:29Z","database_specific":{"nvd_published_at":"2026-04-15T04:17:39Z","cwe_ids":["CWE-565"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-14T22:32:29Z"},"references":[{"type":"WEB","url":"https://github.com/s9y/Serendipity/security/advisories/GHSA-4m6c-649p-f6gf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39963"},{"type":"PACKAGE","url":"https://github.com/s9y/Serendipity"},{"type":"WEB","url":"https://github.com/s9y/Serendipity/releases/tag/2.6.0"}],"affected":[{"package":{"name":"s9y/serendipity","ecosystem":"Packagist","purl":"pkg:composer/s9y/serendipity"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1-beta1","2.1-beta2","2.1-beta3","2.1-rc1","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.2.1-alpha1","2.3-beta1","2.3-rc1","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.4-beta1","2.4.0","2.5-beta1","2.5.0","2.6-beta1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-4m6c-649p-f6gf/GHSA-4m6c-649p-f6gf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}