{"id":"CVE-2026-41113","details":"sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.","modified":"2026-07-15T01:49:05.241962641Z","published":"2026-04-16T22:02:10.225Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41113.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/18/5"},{"type":"WEB","url":"https://github.com/califio/publications/tree/main/MADBugs/qmail"},{"type":"WEB","url":"https://github.com/sagredo-dev/qmail/releases/tag/v2026.04.07"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41113.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41113"},{"type":"FIX","url":"https://github.com/sagredo-dev/qmail/commit/749f607f6885e3d01b36f2647d7a1db88f1ef741"},{"type":"FIX","url":"https://github.com/sagredo-dev/qmail/pull/42"},{"type":"ARTICLE","url":"https://blog.calif.io/p/we-asked-claude-to-audit-sagredos"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sagredo-dev/qmail","events":[{"introduced":"e079d943b0d910ab49f07687cef906f9e28b87f9"},{"fixed":"b5168117cdfc15eba30ee7d42d604122d6eaf4d4"}],"database_specific":{"extracted_events":[{"introduced":"2024.10.26"},{"fixed":"2026.04.07"}],"source":"AFFECTED_FIELD"}}],"versions":["v2026.04.02","v2026.02.25","v2026.02.03","v2026.01.08","v2026.01.05","v2025.09.08","v2025.07.10","v2025.06.09","v2025.04.30","v2025.04.25","v2025.04.18","v2025.02.11","v2024.12.01","v2024.11.27","v2024.11.10","v2024.10.26"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41113.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}