๐Ÿ” CVE Alert

CVE-2026-85751

CRITICAL 9.8

Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3.

CWE CWE-290 CWE-807
Vendor mailu
Product mailu
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for mailu mailu

Be the first to know when new critical vulnerabilities affecting mailu mailu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Mailu / Mailu
>= 2.0.0, < 2024.06.55
Mailu / helm-charts
< 2.7.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Mailu/Mailu/security/advisories/GHSA-rfhj-4wcq-74xg github.com: https://github.com/Mailu/Mailu/pull/4070 github.com: https://github.com/Mailu/Mailu/pull/4071 github.com: https://github.com/Mailu/Mailu/commit/dffa97cbd889ab208246372ce9c86e99abb27ae9 github.com: https://github.com/Mailu/Mailu/commit/ff4003d045753013470945336448dbd790cac778 github.com: https://github.com/Mailu/Mailu/releases/tag/2024.06.55