{"id":"GHSA-527g-3w9m-29hv","summary":"mitmproxy has an LDAP Injection","details":"### Impact\nIn mitmproxy 12.2.1 and below, the builtin LDAP proxy authentication does not correctly sanitize the username when querying the LDAP server. This allows a malicious client to bypass authentication.\n\nOnly mitmproxy instances using the `proxyauth` option with LDAP are affected. This option is not enabled by default.\n\n### Patches\n\nThe vulnerability has been fixed in mitmproxy 12.2.2 and above.\n\n### Acknowledgements\n\nWe thank Yue (Knox) Liu (@yueyueL) for responsibly disclosing this vulnerability to the mitmproxy team.\n\n### Timeline\n\n- **2025-12-08**: Received initial report. \n- **2025-12-09**: Verified report and confirmed receipt.\n- **2026-01-02**: Informed researcher that patch will be part of the next regular patch release.\n- **2026-04-12**: Published patch release and advisory.","aliases":["CVE-2026-40606","PYSEC-2026-92"],"modified":"2026-06-06T01:15:07.895536978Z","published":"2026-04-14T01:08:52Z","database_specific":{"nvd_published_at":"2026-04-21T18:16:52Z","cwe_ids":["CWE-90"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-14T01:08:52Z"},"references":[{"type":"WEB","url":"https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-527g-3w9m-29hv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40606"},{"type":"PACKAGE","url":"https://github.com/mitmproxy/mitmproxy"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mitmproxy/PYSEC-2026-92.yaml"}],"affected":[{"package":{"name":"mitmproxy","ecosystem":"PyPI","purl":"pkg:pypi/mitmproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.2.2"}]}],"versions":["0.10","0.10.1","0.11","0.11.1","0.11.2","0.11.3","0.12.0","0.12.1","0.13","0.14.0","0.15","0.16","0.17","0.18.1","0.18.2","0.18.3","0.8","0.8.1","0.9","0.9.1","0.9.2","1.0.0","1.0.1","1.0.2","10.0.0","10.1.0","10.1.1","10.1.2","10.1.3","10.1.4","10.1.5","10.1.6","10.2.0","10.2.1","10.2.2","10.2.3","10.2.4","10.3.0","10.3.1","10.4.0","10.4.1","10.4.2","11.0.0","11.0.1","11.0.2","11.1.0","11.1.2","11.1.3","12.0.0","12.0.1","12.1.0","12.1.1","12.1.2","12.2.0","12.2.1","2.0.0","2.0.1","2.0.2","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","4.0.0","4.0.1","4.0.3","4.0.4","5.0.0","5.0.1","5.1.0","5.1.1","5.2","5.3.0","6.0.0","6.0.1","6.0.2","7.0.0","7.0.1","7.0.2","7.0.3","7.0.4","8.0.0","8.1.0","8.1.1","9.0.0","9.0.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 12.2.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-527g-3w9m-29hv/GHSA-527g-3w9m-29hv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}