top of page
perceptive_background_267k.jpg

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usern…

Published:

15 april 2026 om 22:00:00

Alert date:

16 april 2026 om 01:02:25

Source:

nvd.nist.gov

Click to open the original link from this advisory

Email & Messaging, Identity & Access

The maddy mail server versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module. User-supplied usernames are interpolated into LDAP search filters without proper escaping, despite available sanitization functions. Attackers with network access to SMTP or IMAP interfaces can inject arbitrary LDAP filter expressions through AUTH PLAIN or LOGIN commands. This enables identity spoofing, LDAP directory enumeration, and blind extraction of attribute values. The vulnerability affects three code paths: Lookup() filter, AuthPlain() DN template, and AuthPlain() filter. Fixed in version 0.9.3.

Technical details

Mitigation steps:

Affected products:

maddy mail server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page