<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:41:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-234380</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234380</link>
      <description>EUVD-2026-234380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234380</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24732</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24732</link>
      <description>&lt;p&gt;Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24732</guid>
    </item>
    <item>
      <title>GHSA-6cp7-g972-w9m9 — Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6cp7-g972-w9m9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/foxcpp/maddy&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any configuration on any maddy version &amp;lt;0.5.4 using auth.pam is affected.&lt;/p&gt;
&lt;p&gt;No password expiry or account expiry checking is done when authenticating using PAM.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patch is available as part of the 0.5.4 release.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected.&lt;/p&gt;
&lt;p&gt;It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql).&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://github.com/foxcpp/maddy/blob/3412e59a2c92106e194fa69f2f1017c020037c9c/internal/auth/pam/pam.c
* https://linux.die.net/man/3/pam_acct_mgmt&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/foxcpp/maddy
* Email fox.cpp@disroot.org&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/foxcpp/maddy&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any configuration on any maddy version &amp;lt;0.5.4 using auth.pam is affected.&lt;/p&gt;
&lt;p&gt;No password expiry or account expiry checking is done when authenticating using PAM.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patch is available as part of the 0.5.4 release.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected.&lt;/p&gt;
&lt;p&gt;It is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql).&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://github.com/foxcpp/maddy/blob/3412e59a2c92106e194fa69f2f1017c020037c9c/internal/auth/pam/pam.c
* https://linux.die.net/man/3/pam_acct_mgmt&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/foxcpp/maddy
* Email fox.cpp@disroot.org&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6cp7-g972-w9m9</guid>
    </item>
    <item>
      <title>gsd-2022-24732</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24732</link>
      <description>gsd-2022-24732</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24732</guid>
    </item>
  </channel>
</rss>
