References https://nvd.nist.gov/vuln/detail/CVE-2025-40630 https://github.com/advisories/GHSA-hf55-g8pm-mm27 https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-icewarp-mail-server https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-40630.yaml https://cve.akaoma.com/cve-2025-40630 https://cert.kenet.or.ke/cve-2025-40630-icewarp-mail-server-open-redirection-vulnerability https://s4e.io/tools/icewarp-mail-server-open-redirect-cve-2025-40630 https://cve.imfht.com/detail/CVE-2025-40630?lang=en
Related VulnerabilitiesPoCCVE-2026-55552: Yamcs <=5.11.12 - Arbitrary File ReadPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposurePoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated InitializePoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposureCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code ExecutionPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-56292: AcyMailing < 10.11.1 - Unauthenticated SQL InjectionPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership BypassPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure