TGViewer
Proxy Bar Proxy Bar @proxy_bar · 21.5K subscribers
Post #3420 5.09K
CVE-2026-41873: Apache Pony Mail OAuth SSRF + Lua CRLF Smuggling = Unauthenticated Account Takeover

Original: This article is an independent of “(CVE-2026-41873) Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover”, by Li Jiantao and Tevel Sho, published on STAR Labs SG on 28 April 2026.

All vulnerability research, the PoC scripts, the Elasticsearch SQL exfiltration chain, the CRLF / HTTP-request-smuggling payload analysis, and the patch-diff…

https://core-jmp.org/2026/05/cve-2026-41873-apache-pony-mail-ssrf-crlf-rewrite/
  • 🔥 6
  • 👍 4
More from @proxy_bar
  1. Sep 24, 2026Вспомнилось ! Был такой хороший гайд Introduction to Exploit Development Сегодня он интере…
  2. Sep 23, 2026Linux container escape * PoC
  3. Sep 21, 2026Идея для "быстрых свиданий" Ну это те, которые 5 минут общаешься, потом пересаживаетесь. З…
  4. Sep 20, 2026А скиньте фотки с тусы а )))
  5. Sep 20, 2026ZeroNights 2026 подъехали ПРОМОКОДЫ * Действовать начинает с 20 сентября и по 24 сентября…
  6. Sep 19, 2026LPE quartet of Linux local root * DirtyAH6 CVE-2026-80844 POC TUNderflow CVE-2026-81000 PO…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →