VYPR

Mailu

by Mailu

Source repositories

CVEs (3)

  • CVE-2026-85751CriSep 21, 2026
    risk 0.57cvss 9.8epss 0.01

    Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy…

  • CVE-2020-5239HigFeb 13, 2020
    risk 0.57cvss 8.7epss 0.01

    In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most impacted. The master and 1.7 branches are patched on our git…

  • CVE-2026-49217HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided…