CVE-2021-44227High· 8.0▾ TwilightA Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.7%
0.7% → 0.7%
Last analysed / modified upstream
8.8 → 8
8 → 8.8
8.8 → 8
A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be used by an admin to perform an admin-level request, effectively bypassing the protection provided by CSRF tokens. A remote attacker with an account on the mailman system can use this flaw to perform a CSRF attack and perform operations on behalf of the victim admin.
mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover — rated Important by Red Hat. Released 2021-11-26, updated 2026-09-07.
Affected:
Fixed:
No fix planned:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:4913 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:5081 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:5080
Workarounds / mitigations:
Affected packages:
mailman < 2.1.38Patched in:
mailman 2.1.38Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-18165Medium· 4.2@fastify/oauth2 is an OAuth 2.0 plugin for Fastify
CVE-2026-96889High· 7.8A flaw was found in librsvg
CVE-2026-97177Medium· 6.6A flaw was found in the user update mechanism of the Keycloak Admin REST API
CVE-2026-97176Medium· 4.2A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution
CVE-2026-75887High· 7.5A flaw was found in the OpenShift console
CVE-2026-75886High· 7.2A flaw was found in openshift/console