


Perceptive Security
SOC/SIEM Consultancy

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usern…
Published:
15 april 2026 om 22:00:00
Alert date:
16 april 2026 om 01:02:25
Source:
nvd.nist.gov
Email & Messaging, Identity & Access
The maddy mail server versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module. User-supplied usernames are interpolated into LDAP search filters without proper escaping, despite available sanitization functions. Attackers with network access to SMTP or IMAP interfaces can inject arbitrary LDAP filter expressions through AUTH PLAIN or LOGIN commands. This enables identity spoofing, LDAP directory enumeration, and blind extraction of attribute values. The vulnerability affects three code paths: Lookup() filter, AuthPlain() DN template, and AuthPlain() filter. Fixed in version 0.9.3.
Technical details
Mitigation steps:
Affected products:
maddy mail server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40193
https://github.com/foxcpp/maddy/commit/6a06337eb41fa87a35697366bcb71c3c962c44ba
https://github.com/foxcpp/maddy/releases/tag/v0.9.3
https://github.com/foxcpp/maddy/security/advisories/GHSA-5835-4gvc-32pc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
