HTML Rendering Vulnerability in Postorius by Mailman
CVE-2026-44742

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-44742?

The Postorius web interface for Mailman, versions up to 1.3.13, is affected by a vulnerability that fails to properly escape HTML in the message subject line displayed in the Held messages pop-up. This oversight potentially allows attackers to inject malicious HTML content, which could lead to unauthorized actions when users interact with the interface. The vulnerability has been observed to be exploited in real-world scenarios as of May 2026, raising significant security concerns for users relying on this functionality.

Affected Version(s)

Postorius 0 <= 1.3.13

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.