CVE-2026-25529Disclosure(postalserver / postal)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for unescaped data to be added is via the API's "send/raw" method. This could allow arbitrary HTML to be injected in to the page which may modify the page in a misleading way or allow for unauthorised javascript to be executed. Fixed in 3.3.5 and higher.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postal

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
postal

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-12: 3Technical Details · 2026-03-12: 303-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25529 HTML Injection Vulnerability in Postal SMTP Server Versions Below 3.3.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25529

    Post summary

    The post announces CVE‑2026‑25529 as an HTML injection flaw in Postal SMTP Server versions below 3.3.5, linking to a vulnerability detail page but providing no PoC, exploit code, patch information, or evidence of active exploitation.

    0001028
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25529 Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin inter… https://www.cve.org/CVERecord?id=CVE-2026-25529

    Post summary

    The post announces CVE-2026-25529, noting a HTML injection flaw affecting Postal SMTP servers prior to version 3.3.5, where unescaped data can infiltrate the admin interface.

    00000174
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25529 - High Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for... https://www.thehackerwire.com/vulnerability/CVE-2026-25529/ https://t.co/FB6Jtq6cVB

    Post summary

    The post announces CVE-2026-25529 as a high‑severity HTML injection issue in Postal <3.3.5 that permits unescaped data in the admin interface, without mentioning PoC, exploit, or mitigation details.

    0000032
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostalserverpostal---

Explore more