Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.7 PHP packages GHSA-mfxh-vp55-7gc6 CVE-2026-107843 PKSA-s71c-hg32-kv3f

CVE-2026-107843 — Contao registration module re-sends activation mails

A logic flaw in Contao's registration module can be triggered by unauthenticated POST requests to resend activation emails without rate limiting, allowing repeated emails and an observable difference that reveals whether a pending registration exists. Fixed in vendor updates.

AI summary

CVE-2026-107843 affects contao/core-bundle. The registration module can be driven into a follow-up branch by POST requests without verifying FORM_SUBMIT or a captcha result; this allows resendActivationMail() to call OptInToken::send() without rate limiting. Vendor fixes are available.

What happened

Contao's registration module can enter a follow-up registration branch on any POST to a page containing the registration module without checking FORM_SUBMIT or the preceding captcha. That lets resendActivationMail() invoke OptInToken::send() without rate limiting, enabling repeated activation emails to be sent to an address with a pending registration and producing an observable response difference that reveals whether such a pending registration exists.

Technical cause

ModuleRegistration::compile() does not verify FORM_SUBMIT or the prior captcha result before taking its follow-up registration branch on POST. The follow-up path leads to resendActivationMail(), which can call OptInToken::send() without any built-in rate limiting. The branch is only reachable when reg_activate is enabled and the target has an unconfirmed registration and an opt-in token.

Why it matters

An unauthenticated attacker can trigger repeated activation emails to an address that already has a pending registration and can observe responses to determine whether a pending registration exists for that address. There is no public exploit known in the sources.

Who is affected

Installations using contao/core-bundle with reg_activate enabled and with unconfirmed registrations (opt-in tokens present) are affected. The vulnerability is reachable via unauthenticated POST requests to pages that include the registration module.

Discovery and timeline

The advisory was published on 2026-10-09. The issue is recorded in OSV, the GitHub Advisory Database / Packagist advisory, and in NVD under CVE-2026-107843.

Affected versions

Packages of contao/core-bundle in the ranges >= 4.1.0 and < 5.3.50, and >= 5.4.0-RC1 and < 5.7.12 are reported as affected.

Fixes and mitigation

The issue is fixed in the vendor updates contao/core-bundle 5.3.50 and 5.7.12. Sources list those fixed versions; a patch is available.

Recommended action

Update contao/core-bundle to one of the fixed releases (5.3.50 or 5.7.12) as provided by the vendor advisory. Verify that pages exposing the registration module are covered by the update.

PatchBriefing score

3.7 / 10 · Low

Official CVSS: 5.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Why this score

CVSS v3.1 base score 5.3 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Patchwire score 3.7 factors include unauthenticated remote access and no required user interaction; there are no known public exploits recorded in the sources.

Affected versions

contao/core-bundle ≥ 5.4.0-RC1 < 5.7.12
vulnerable
contao/core-bundle
vulnerable
contao/core-bundle >=5.4.0-RC1,<5.7.12|>=4.1.0,<5.3.50
vulnerable
contao/core-bundle >= 5.4.0-RC1, < 5.7.12
vulnerable
≥ 5.3.50
patched
≥ 5.7.12
patched

Reported fixes

The issue is fixed in the vendor updates contao/core-bundle 5.3.50 and 5.7.12. Sources list those fixed versions; a patch is available.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • Packagist Security Advisories registry
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
CVE-2026-107843 — Contao registration module re-sends activation mails
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email