Back to overview

CVE-2026-41873

CRITICAL
9.8
CVSS 3.1
Description
** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name "Pony Mail Foal" that is not affected by this issue, but hasn't been released yet. As the Lua implementation of this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Metadata

CVE ID
CVE-2026-41873
State
PUBLISHED
Assigner
apache
Reserved
2026-04-22 09:10 UTC
Published
2026-04-28 15:18 UTC
Last updated
2026-04-29 11:55 UTC
Primary CWE
CWE-444
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP …
Vendor / Product
Apache Software Foundation / Pony Mail
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Apache Software Foundation Pony Mail 0 ≤ *
Weakness (CWE)
CWESourceDescription
CWE-444 cna CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview