CVE-2025-59937
Błędne przetwarzanie adresów w go-mail umożliwia nieprawidłowe routowanie wiadomości.
go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of the mail.Address values when a sender- or recipient address is passed to the corresponding MAIL FROM or RCPT TO commands of the SMTP client, there is a possibility of wrong address routing or even ESMTP parameter smuggling. For successful exploitation, it is required that the user's code allows for arbitrary mail address input (i. e. through a web form or similar). If only static mail addresses are used (i. e. in a config file) and the mail addresses in use do not consist of quoted local parts, this should not affect users. This issue is fixed in version 0.7.1
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-09-29 23:15:31 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 09:10:00 UTC |
- https://github.com/wneessen/go-mail/commit/42e92cfe027be04aff72921adb0f72f11d517479 ([email protected]) [Patch]
- https://github.com/wneessen/go-mail/issues/495 ([email protected]) [Exploit, Issue Tracking]
- https://github.com/wneessen/go-mail/pull/496 ([email protected]) [Issue Tracking, Patch]
- https://github.com/wneessen/go-mail/security/advisories/GHSA-wpwj-69cm-q9c5 ([email protected]) [Vendor Advisory]