Skip to main content

Vendor/product archive

maddy_project / maddy CVEs

Beta · best-effort

3 CVEs tagged to maddy_project / maddy1 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-40193

Published Apr 16, 2026

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolat…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-27582

Published Mar 13, 2023

maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24732

Published Mar 9, 2022

Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1