CVE-2026-85751

Source
https://cve.org/CVERecord?id=CVE-2026-85751
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85751.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85751
Aliases
  • GHSA-rfhj-4wcq-74xg
Published
2026-09-21T15:39:24Z
Modified
2026-09-23T03:47:30Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust
Details

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-290",
        "CWE-807"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85751.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "2.7.3"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mailu/mailu

Affected ranges

Type
GIT
Repo
https://github.com/mailu/mailu
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.0.0"
        },
        {
            "fixed":  "2024.06.55"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0.0
2024.*
2024.06.0
2024.06.1
2024.06.10
2024.06.11
2024.06.12
2024.06.13
2024.06.14
2024.06.15
2024.06.16
2024.06.17
2024.06.18
2024.06.19
2024.06.2
2024.06.20
2024.06.21
2024.06.22
2024.06.23
2024.06.24
2024.06.25
2024.06.26
2024.06.27
2024.06.28
2024.06.29
2024.06.3
2024.06.30
2024.06.31
2024.06.32
2024.06.33
2024.06.34
2024.06.35
2024.06.36
2024.06.37
2024.06.38
2024.06.39
2024.06.4
2024.06.40
2024.06.41
2024.06.42
2024.06.43
2024.06.44
2024.06.45
2024.06.46
2024.06.47
2024.06.48
2024.06.49
2024.06.5
2024.06.50
2024.06.51
2024.06.52
2024.06.53
2024.06.54
2024.06.6
2024.06.7
2024.06.8
2024.06.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85751.json"