CVE-2025-31135

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 20

Summary

CVE-2025-31135 affects the Go-Guerrilla SMTP Daemon, a lightweight Go-based SMTP server, prior to version 1.6.7. The issue lies in the handling of PROXY commands when ProxyOn is enabled. The server accepts multiple PROXY commands, overriding earlier ones, and mistakenly treats subsequent PROXY commands as coming from the reverse proxy. This vulnerability allows clients to spoof their IP addresses during communication with the server, posing a potential security risk. Version 1.6.7 addresses this issue by properly managing PROXY commands to prevent IP address spoofing.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share