GNU Vulnerabilities and Affected Products
Vulnerabilities associated with Mailman.
Products
Clear product- Binutils31 vulnerabilities
- grub213 vulnerabilities
- LibreDWG11 vulnerabilities
- PSPP8 vulnerabilities
- elfutils6 vulnerabilities
- Emacs6 vulnerabilities
- Bourne-Again Shell (Bash)5 vulnerabilities
- inetutils5 vulnerabilities
- gawk4 vulnerabilities
- gdb4 vulnerabilities
- cflow3 vulnerabilities
- cpio3 vulnerabilities
- glibc3 vulnerabilities
- GNU C Library (glibc)3 vulnerabilities
- GNU SASL3 vulnerabilities
- Mailman3 vulnerabilities
- Bison2 vulnerabilities
- coreutils2 vulnerabilities
- GCC2 vulnerabilities
- GnuPG2 vulnerabilities
- Guix2 vulnerabilities
- gzip2 vulnerabilities
- Libgcrypt2 vulnerabilities
- ncurses2 vulnerabilities
- patch2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-43921MEDIUM | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used. CWE-863Apr 20, 2025 | CVSS5.3v3.1 | EPSS0.432% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43920MEDIUM | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used. CWE-78Apr 20, 2025 | CVSS5.4v3.1 | EPSS0.562% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43919MEDIUM | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used. | CVSS5.8v3.1 | EPSS1.35% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |