LDAP Proxy Authentication Bypass in mitmproxy by MitmProxy Team
CVE-2026-40606

4.8MEDIUM

Key Information:

Vendor

Mitmproxy

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40606?

In the versions of mitmproxy prior to 12.2.2, a vulnerability exists within the LDAP proxy authentication mechanism. The software does not properly sanitize the username passed to the LDAP server, allowing an attacker utilizing a malicious client to bypass authentication requirements. This issue specifically impacts setups that use the proxyauth feature in conjunction with LDAP, a non-default configuration. Users are advised to upgrade to mitmproxy version 12.2.2 or later to mitigate this risk.

Affected Version(s)

mitmproxy < 12.2.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.