blob: 0918f19fa64eba6ee670c14c453f31ca105aad10 [file] [log] [blame]
id: GO-2025-3588
modules:
- module: github.com/phires/go-guerrilla
versions:
- fixed: 1.6.7
vulnerable_at: 1.6.6
summary: Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple times in github.com/phires/go-guerrilla
cves:
- CVE-2025-31135
ghsas:
- GHSA-c2c3-pqw5-5p7c
references:
- advisory: https://github.com/phires/go-guerrilla/security/advisories/GHSA-c2c3-pqw5-5p7c
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-31135
- fix: https://github.com/phires/go-guerrilla/commit/7673947f2d5204a135d7ae0b7f80759e548abee6
source:
id: GHSA-c2c3-pqw5-5p7c
created: 2025-04-02T11:30:59.679338-04:00
review_status: UNREVIEWED