CVE-2026-41873Disclosure(apache / pony_mail)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache pony_mail systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name "Pony Mail Foal" that is not affected by this issue, but hasn't been released yet. As the Lua implementation of this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pony_mail

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-28); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
pony_mail

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-28: 4Mentions · 2026-04-29: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-28: 4Technical Details · 2026-04-29: 104-2804-2905-12
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-284
Disclosure3Patch1
2026-04-291
Disclosure1
2026-05-121
Disclosure1
Full discourse6 posts
  • starlabs@starlabs_sg
    Disclosure

    We spent almost 2 years seeing this disclosure through… and then accidentally forgot to post it here. 😅 Never gonna give you up. Never gonna let you down. Never gonna run around and forget the advisory. CVE-2026-41873 is now public: https://starlabs.sg/advisories/26/26-41873/

    Post summary

    The post announces CVE-2026-41873 as a newly public vulnerability with a link to an advisory; no PoC, exploit, or technical details are supplied.

    011066264.2K
    10.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41873: Pony Mail: Admin account takeover via request smuggling https://www.openwall.com/lists/oss-security/2026/04/28/17 Severity: critical

    Post summary

    A critical vulnerability (CVE‑2026‑41873) in Pony Mail allows admins to be taken over via request smuggling.

    040100562
    4.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-41873 — CVSS 9.8/10 ██████████ ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/HZWyrNm6kY

    Post summary

    CVE‑2026‑41873 is a critical HTTP Request/Response Smuggling vulnerability with a CVSS score of 9.8/10, and a patch is now available.

    1001043
    25 followersView on X
  • ThreatLevel@ThreatLevelAI
    Disclosure

    🚨 New vulnerability Authentication Bypass in Apache Pony Mail (CVE-2026-41873) 📊 CVSS Score: 9.8 (Critical) 🔐 No authentication required ⚙️ Exploitable in default configuration 🌐 Mixed internet/internal deployment 🎯 ThreatLevel Priority: Fix Soon Full analysis 👇 https://threatlevel.io/CVE-2026-41873?utm_source=x&utm_campaign=JNWQjBQ-

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-41873) in Apache Pony Mail has been disclosed with a CVSS score of 9.8 and requires no authentication, making it exploitable in default configurations. No PoC, exploit code, or mitigation details are provided, and there is no evidence of active exploitation.

    0001040
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41873 ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account t… https://www.cve.org/CVERecord?id=CVE-2026-41873

    Post summary

    The text announces CVE-2026-41873, detailing a HTTP request smuggling flaw in Pony Mail, but does not provide a PoC, exploit, or patch information.

    00000118
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41873 HTTP Request Smuggling Vulnerability in Pony Mail Leading to Admin Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41873

    Post summary

    A newly reported HTTP Request Smuggling vulnerability in Pony Mail (CVE‑2026‑41873) enables attackers to take over admin accounts, but no PoC, exploit, active exploitation, patch or debunking information is provided.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepony_mail---

Explore more