PT-2025-14443 · Unknown · Go-Guerrilla Smtp Daemon

Published

2025-04-01

·

Updated

2026-01-28

·

CVE-2025-31135

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Go-Guerrilla SMTP Daemon versions prior to 1.6.7
Description The issue allows a client to spoof its IP address when the proxy protocol is being used. This occurs because the PROXY command is accepted multiple times, with later invocations overriding earlier ones. The proxy protocol only supports one initial PROXY header, and any subsequent PROXY commands are treated as part of the exchange between the client and server, enabling the client to send further PROXY commands with arbitrary data. This is then treated by go-guerrilla as coming from the reverse proxy.
Recommendations For Go-Guerrilla SMTP Daemon versions prior to 1.6.7, update to version 1.6.7 to resolve the issue. As a temporary workaround, consider disabling the ProxyOn feature until a patch is available. Restrict access to instances with ProxyOn enabled to minimize the risk of exploitation. Avoid using the PROXY command in the affected protocol until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-31135
GHSA-C2C3-PQW5-5P7C
GO-2025-3588
OPENSUSE-SU-2025:14970-1

Affected Products

Go-Guerrilla Smtp Daemon