HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15437 HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Fixes

Solution

The vulnerabilities have been fixed by the IceWarp team in the 13.0.2 version.


Workaround

No workaround given by the vendor.

History

Thu, 09 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Icewarp
Icewarp mail Server
CPEs cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:*
Vendors & Products Icewarp
Icewarp mail Server
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 16 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 11:15:00 +0000

Type Values Removed Values Added
Description HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Title HTTP host header injection vulnerability in IceWarp Mail Server
Weaknesses CWE-644
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-05-16T13:46:34.760Z

Reserved: 2025-04-16T08:38:09.209Z

Link: CVE-2025-40631

cve-icon Vulnrichment

Updated: 2025-05-16T13:15:30.500Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-16T11:15:45.690

Modified: 2025-10-09T19:31:54.423

Link: CVE-2025-40631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.