GHSA-4g76-w3xw-2x6w · Severity: critical · Ecosystem: go — Full authentication bypass if SASL authorization username is specified
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified username, it is accepted as is after checking the credentials for the authentication username. maddy 0.6.3 includes the fix for the bug. There are no known workarounds.
Conclusion & alert: CVE-2023-27582 is rated Moderate Risk (57.4/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.02%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.57% | 1.02% | +0.45% |
| 2 | 2026-05-12 | 0.24% | 0.57% | +0.33% |
| 3 | 2026-03-27 | — | 0.24% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-4g76-w3xw-2x6w · Severity: critical · Ecosystem: go — Full authentication bypass if SASL authorization username is specified
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
critical | CVE-2023-27582: 1 source package rows (maddy); 1 state rows across 1 repos (edge-community); fixed 1, open 0. | https://security.alpinelinux.org/vuln/CVE-2023-27582 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| maddy_project | maddy | >= 0.2.0, < 0.6.3 | cpe:2.3:a:maddy_project:maddy:*:*:*:*:*:*:*:* |