CVE-2025-25198PoC(mailcow / mailcow\)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for mailcow mailcow\ systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link. Version 2025-01a contains a patch. As a workaround, deactivate the password reset functionality by clearing `Notification email sender` and `Notification email subject` under System -> Configuration -> Options -> Password Settings.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mailcow\

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
mailcow\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-18: 1Mentions · 2026-03-07: 1PoC Mentioned / Linked · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-18: 1Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-02-18: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-18: 1Technical Details · 2026-03-07: 102-1202-1803-07
Signal classification2 categories
PoC
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
PoC1
2026-02-181
PoC1
2026-03-071
Disclosure1
Full discourse3 posts
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    Host header poisoning in mailcow:dockerized < 2025-01a allows attackers to craft poisoned password reset links. https://www.redsecuretech.co.uk/blog/post/mailcow-host-header-poisoning-cve-2025-25198-explained/1003 #CyberSecurity #Mailcow #CVE #HostHeaderPoisoning #PasswordReset #EmailSecurity #DockerSecurity #InfoSec #OpenSource #Vulnerability https://t.co/E7tJzxBZaN

    Post summary

    The tweet announces a host header poisoning vulnerability in mailcow:dockerized versions prior to 2025‑01a that enables attackers to craft poisoned password reset links; no PoC, exploit code, or evidence of active attacks is presented.

    01010180
    40 followersView on X
  • Iam Alvarez Orellana@Iam_al_or
    PoC

    Just got my first PoC published on Packet Storm CVE-2025-25198 - Mailcow Host header poisoning. Automated, clean, does the job. Check it out 👇 https://packetstorm.news/files/id/215692/ https://t.co/xrkCPsMr4h

    Post summary

    A PoC for CVE-2025-25198, a Mailcow Host header poisoning vulnerability, has been published on Packet Storm with a link to the code.

    0001057
    4 followersView on X
  • Iam Alvarez Orellana@Iam_al_or
    PoC

    Just dropped a PoC for CVE-2025-25198 Automated Host header poisoning for Mailcow. spins up HTTPS listener, handles cookies + CSRF, catches the reset link right when it lands. No tab hell. Just the link. GitHub: https://github.com/Groppoxx/CVE-2025-25198-PoC.git #CVE #infosec #BugBounty https://t.co/6NC6r42EH0

    Post summary

    The author released a PoC for CVE‑2025‑25198, demonstrating automated host‑header poisoning against Mailcow and sharing the code via a GitHub repository.

    0001084
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmailcowmailcow\_dockerized--

Explore more