<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:32:46.554134+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234380</id>
    <title>EUVD-2026-234380</title>
    <updated>2026-10-02T20:32:46.650782+00:00</updated>
    <content>EUVD-2026-234380</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24732</id>
    <title>fkie_cve-2022-24732</title>
    <updated>2026-10-02T20:32:46.650827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6cp7-g972-w9m9</id>
    <title>GHSA-6cp7-g972-w9m9 — Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server</title>
    <updated>2026-10-02T20:32:46.650878+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/foxcpp/maddy</p>
<p>### Impact</p>
<p>Any configuration on any maddy version &lt;0.5.4 using auth.pam is affected.</p>
<p>No password expiry or account expiry checking is done when authenticating using PAM.</p>
<p>### Patches</p>
<p>Patch is available as part of the 0.5.4 release.</p>
<p>### Workarounds</p>
<p>If /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected.</p>
<p>It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql).</p>
<p>### References</p>
<p>* https://github.com/foxcpp/maddy/blob/3412e59a2c92106e194fa69f2f1017c020037c9c/internal/auth/pam/pam.c
* https://linux.die.net/man/3/pam_acct_mgmt</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/foxcpp/maddy
* Email fox.cpp@disroot.org</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6cp7-g972-w9m9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24732</id>
    <title>gsd-2022-24732</title>
    <updated>2026-10-02T20:32:46.650946+00:00</updated>
    <content>gsd-2022-24732</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24732"/>
  </entry>
</feed>
