Orizon[verified]@OrizonCyberPatch
CVE‑2026‑41873 is a critical HTTP Request/Response Smuggling vulnerability with a CVSS score of 9.8/10, and a patch is now available.
starlabs@starlabs_sgDisclosure
The post announces CVE-2026-41873 as a newly public vulnerability with a link to an advisory; no PoC, exploit, or technical details are supplied.
Open Source Security mailing list@oss_securityDisclosure
A critical vulnerability (CVE‑2026‑41873) in Pony Mail allows admins to be taken over via request smuggling.
ThreatLevel@ThreatLevelAIDisclosure
A critical authentication bypass vulnerability (CVE-2026-41873) in Apache Pony Mail has been disclosed with a CVSS score of 9.8 and requires no authentication, making it exploitable in default configurations. No PoC, exploit code, or mitigation details are provided, and there is no evidence of active exploitation.
CVE@CVEnewDisclosure
The text announces CVE-2026-41873, detailing a HTTP request smuggling flaw in Pony Mail, but does not provide a PoC, exploit, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A newly reported HTTP Request Smuggling vulnerability in Pony Mail (CVE‑2026‑41873) enables attackers to take over admin accounts, but no PoC, exploit, active exploitation, patch or debunking information is provided.