CVE-2026-85751
- EPSS 0.56%
- Veröffentlicht 21.09.2026 15:39:24
- Zuletzt bearbeitet 24.09.2026 21:25:27
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By h...
CVE-2026-49217
- EPSS -
- Veröffentlicht 20.08.2026 22:17:19
- Zuletzt bearbeitet 18.09.2026 20:09:01
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any e...
CVE-2020-5239
- EPSS 0.89%
- Veröffentlicht 13.02.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:44
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most impacted. The master and 1.7 bran...