← Vulnerability feed

Vulnerability record · CVE-2026-40193 · published 16 April 2026

CVE-2026-40193: Maddy project maddy ldap injection vulnerability

Maddy Project · Maddy

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's ldap.EscapeFilter() function being available in the same import. This affects three code paths: the Lookup() filter, the AuthPlain() DN template, and the AuthPlain() filter. An attacker with network access to the SMTP submission or IMAP interface can inject arbitrary LDAP filter expressions through the username field in AUTH PLAIN or LOGIN commands. This enables identity spoofing by manipulating filter results to authenticate as another user, LDAP directory enumeration via wildcard filters, and blind extraction of LDAP attribute values using authentication responses as a boolean oracle or via timing side-channels between the two distinct failure paths. This issue has been fixed in version 0.9.3.

8.2 CVSS 3.1 High EPSS 0.52% · top 58.0% CWE-90 · LDAP injection
8.2CVSS 3.1 base score
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's ldap.EscapeFilter() function being available in the same import. This affects three code paths: the Lookup() filter, the AuthPlain() DN template, and the AuthPlain() filter. An attacker with network access to the SMTP submission or IMAP interface can inject arbitrary LDAP filter expressions through the username field in AUTH PLAIN or LOGIN commands. This enables identity spoofing by manipulating filter results to authenticate as another user, LDAP directory enumeration via wildcard filters, and blind extraction of LDAP attribute values using authentication responses as a boolean oracle or via timing side-channels between the two distinct failure paths. This issue has been fixed in version 0.9.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40193 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27582Maddy project maddy improper authentication vulnerabilitymaddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if S…EPSS 1.0%8.8CVE-2022-24732Maddy project maddy insufficient session expiration vulnerabilityMaddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry…EPSS 0.41%7.8CVE-2026-85880Windows ALPC heap buffer overflow allows local privilege escalationA heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local acce…KEVEPSS 3.6%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed5.5CVE-2024-50302Linux kernel HID core uninitialized report buffer leaks kernel memoryThe Linux kernel HID core allocates a report buffer without zero-initializing it, so residual kernel memory can be exposed through crafted HID report…KEVEPSS 0.81%analysed5.5CVE-2024-29745Android Pixel firmware uninitialized data information disclosureCVE-2024-29745 is an information disclosure flaw in Android on Pixel devices caused by use of uninitialized data (CWE-908). A local attacker can read…KEVEPSS 0.48%analysed

Source: NIST National Vulnerability Database (record CVE-2026-40193), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.