PatchSiren

forem CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH forem CVE published 2026-06-16

CVE-2026-48780

CVE-2026-48780 is a HIGH severity vulnerability in Forem community software. A maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only Forem deployments. The issue was patched in commit [a2ab6d4](resourceLinkAnnotations:ref-4). As a workaround, some SMTP servers and email delivery providers may drop or refuse to send mali [truncated]