GHSA-527g-3w9m-29hv

Suggest an improvement
Source
https://github.com/advisories/GHSA-527g-3w9m-29hv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-527g-3w9m-29hv/GHSA-527g-3w9m-29hv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-527g-3w9m-29hv
Aliases
Published
2026-04-14T01:08:52Z
Modified
2026-06-06T01:15:07Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
mitmproxy has an LDAP Injection
Details

Impact

In mitmproxy 12.2.1 and below, the builtin LDAP proxy authentication does not correctly sanitize the username when querying the LDAP server. This allows a malicious client to bypass authentication.

Only mitmproxy instances using the proxyauth option with LDAP are affected. This option is not enabled by default.

Patches

The vulnerability has been fixed in mitmproxy 12.2.2 and above.

Acknowledgements

We thank Yue (Knox) Liu (@yueyueL) for responsibly disclosing this vulnerability to the mitmproxy team.

Timeline

  • 2025-12-08: Received initial report.
  • 2025-12-09: Verified report and confirmed receipt.
  • 2026-01-02: Informed researcher that patch will be part of the next regular patch release.
  • 2026-04-12: Published patch release and advisory.
Database specific
{
    "cwe_ids":  [
        "CWE-90"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-14T01:08:52Z",
    "nvd_published_at":  "2026-04-21T18:16:52Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / mitmproxy

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.2.2

Affected versions

0.*
0.8
0.8.1
0.9
0.9.1
0.9.2
0.10
0.10.1
0.11
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13
0.14.0
0.15
0.16
0.17
0.18.1
0.18.2
0.18.3
1.*
1.0.0
1.0.1
1.0.2
2.*
2.0.0
2.0.1
2.0.2
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
4.*
4.0.0
4.0.1
4.0.3
4.0.4
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.2
5.3.0
6.*
6.0.0
6.0.1
6.0.2
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
8.*
8.0.0
8.1.0
8.1.1
9.*
9.0.0
9.0.1
10.*
10.0.0
10.1.0
10.1.1
10.1.2
10.1.3
10.1.4
10.1.5
10.1.6
10.2.0
10.2.1
10.2.2
10.2.3
10.2.4
10.3.0
10.3.1
10.4.0
10.4.1
10.4.2
11.*
11.0.0
11.0.1
11.0.2
11.1.0
11.1.2
11.1.3
12.*
12.0.0
12.0.1
12.1.0
12.1.1
12.1.2
12.2.0
12.2.1

Database specific

last_known_affected_version_range
"<= 12.2.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-527g-3w9m-29hv/GHSA-527g-3w9m-29hv.json"