HTML Injection Vulnerability in mailcow: Dockerized Groupware Suite
CVE-2026-40878
2.1LOW
What is CVE-2026-40878?
An HTML injection vulnerability exists in mailcow: dockerized due to improper handling of $_SERVER['REQUEST_URI'] within the web interface. This flaw allows an attacker to inject malicious scripts through the language-switching links on the login page. The affected versions fail to implement proper context-sensitive escaping, enabling the execution of arbitrary scripts. Mailcow has addressed this issue in version 2026-03b, enhancing the security of its groupware suite.
Affected Version(s)
mailcow-dockerized < 2026-03b
