Skip to content

Navigation Menu

Sign in
Sign up

[SECURITY] maddy 0.9.3 #836

foxcpp announced in Releases
Discussion options

This release includes the fix for the LDAP injection vulnerability
in auth.ldap module (advisory GHSA-5835-4gvc-32pc, CVE-2026-40193).
All users using auth.ldap are advised to upgrade, as this vulnerability
can be used to extract LDAP directory information, including password
hashes and other authorization information.

Thanks @ RealHurrison and @Ghost1032 for detailed report!

Fixes


This discussion was created from the release [SECURITY] maddy 0.9.3.
You must be logged in to vote

Replies: 0 comments

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant

AltStyle によって変換されたページ (->オリジナル) /