Description
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
References (7)
Core 7
Core References
Various Sources
https://github.com/Alinto/sope/blob/3146fbdb6ff3314e37e5c3682deeeef7d0f32064/sope-core/NGExtensions/NGHashMap.m#L790
Various Sources
https://github.com/Alinto/sope/compare/SOGo-2.0.1...SOGo-2.0.2
Issue Tracking
https://github.com/Alinto/sope/pull/69
Scores
CVSS v3
7.5
EPSS
0.0021
EPSS Percentile
43.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (1)
Alinto/SOPE
SOGo 2.0.2 - 5.12.2
Published
Jul 05, 2025
Tracked Since
Feb 18, 2026