github.com/foxcpp/maddy
Activity
- Latest release
- 3mo ago
- Total releases
- 20
- Cadence
- ~23 days
- Last 12 months
- 7
Reach
- Stars
- —
Details
- First release
- Aug 09, 2021
| Version | Released | |
|---|---|---|
v0.9.5
patch
|
v0.9.5
patch
Dependencies (55)
+ 47 more |
|
v0.9.4
patch
|
v0.9.4
patch
Dependencies (55)
+ 47 more |
|
v0.9.3
patch
|
v0.9.3
patch
Dependencies (55)
+ 47 more |
|
v0.9.2
patch
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.9.2
patch
Dependencies (55)
+ 47 more |
|
v0.9.1
patch
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.9.1
patch
Dependencies (55)
+ 47 more |
|
v0.9.0
minor
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.9.0
minor
Dependencies (55)
+ 47 more |
|
v0.8.2
patch
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.8.2
patch
Dependencies (54)
+ 46 more |
|
v0.8.1
patch
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.8.1
patch
Dependencies (53)
+ 45 more |
|
v0.8.0
minor
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (52)
+ 44 more |
|
v0.7.1
patch
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.7.1
patch
Dependencies (50)
+ 42 more |
|
v0.7.0
minor
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (49)
+ 41 more |
|
v0.6.3
patch
1 CVE
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.6.3
patch
Dependencies (47)
+ 39 more |
|
v0.6.2
patch
2 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.2
patch
Dependencies (47)
+ 39 more |
|
v0.6.1
patch
2 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.1
patch
Dependencies (47)
+ 39 more |
|
v0.6.0
minor
2 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (47)
+ 39 more |
|
v0.5.4
patch
2 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.4
patch
Dependencies (50)
+ 42 more |
|
v0.5.3
patch
3 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24732
GHSA-6cp7-g972-w9m9
Mar 07, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
ImpactAny configuration on any maddy version <0.5.4 using auth.pam is affected. No password expiry or account expiry checking is done when authenticating using PAM. PatchesPatch is available as part of the 0.5.4 release. WorkaroundsIf /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected. It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql). References
For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.4
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.5.3
patch
Dependencies (50)
+ 42 more |
|
v0.5.2
patch
3 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24732
GHSA-6cp7-g972-w9m9
Mar 07, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
ImpactAny configuration on any maddy version <0.5.4 using auth.pam is affected. No password expiry or account expiry checking is done when authenticating using PAM. PatchesPatch is available as part of the 0.5.4 release. WorkaroundsIf /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected. It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql). References
For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.4
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.5.2
patch
Dependencies (51)
+ 43 more |
|
v0.5.1
patch
5 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2022-0378
GHSA-qh54-9vc5-m9fg
Aug 21, 2024
MD5 hash support in github.com/foxcpp/maddy MD5 hash support in github.com/foxcpp/maddy Fixed in
0.5.2
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-42583
GO-2022-0306
GHSA-5r5w-h76p-m726
Aug 21, 2024
Use of a Broken or Risky Cryptographic Algorithm in Max Mazurov Maddy in github.com/foxcpp/maddy Use of a Broken or Risky Cryptographic Algorithm in Max Mazurov Maddy in github.com/foxcpp/maddy Fixed in
0.5.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24732
GHSA-6cp7-g972-w9m9
Mar 07, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
ImpactAny configuration on any maddy version <0.5.4 using auth.pam is affected. No password expiry or account expiry checking is done when authenticating using PAM. PatchesPatch is available as part of the 0.5.4 release. WorkaroundsIf /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected. It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql). References
For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.4
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.5.1
patch
Dependencies (51)
+ 43 more |
|
v0.5.0
initial
6 CVEs
CVE-2026-40193
GO-2026-5137
GHSA-5835-4gvc-32pc
Jun 25, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username in github.com/foxcpp/maddy Fixed in
0.9.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2022-0374
GHSA-m6m5-pp4g-fcc8
Aug 21, 2024
S3 storage write is not aborted on errors leading to unbounded memory usage in github.com/foxcpp/maddy S3 storage write is not aborted on errors leading to unbounded memory usage in github.com/foxcpp/maddy Fixed in
0.5.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0378
GHSA-qh54-9vc5-m9fg
Aug 21, 2024
MD5 hash support in github.com/foxcpp/maddy MD5 hash support in github.com/foxcpp/maddy Fixed in
0.5.2
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-42583
GO-2022-0306
GHSA-5r5w-h76p-m726
Aug 21, 2024
Use of a Broken or Risky Cryptographic Algorithm in Max Mazurov Maddy in github.com/foxcpp/maddy Use of a Broken or Risky Cryptographic Algorithm in Max Mazurov Maddy in github.com/foxcpp/maddy Fixed in
0.5.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-27582
GO-2023-1630
GHSA-4g76-w3xw-2x6w
Aug 20, 2024
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy Fixed in
0.6.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24732
GHSA-6cp7-g972-w9m9
Mar 07, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
ImpactAny configuration on any maddy version <0.5.4 using auth.pam is affected. No password expiry or account expiry checking is done when authenticating using PAM. PatchesPatch is available as part of the 0.5.4 release. WorkaroundsIf /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected. It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql). References
For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.4
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.5.0
initial
Dependencies (50)
+ 42 more |