---
id: CVE-2021-44227
title: >-
  mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover
  (CVE-2021-44227)
summary: >-
  A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to
  a CSRF token bypass. CSRF tokens are not checked against the right type of
  user when performing admin operations and a token created by a regular user
  can be use…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-352
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream EUS (v. 8.2)
affected:
  - enterprise_linux 6
  - enterprise_linux_server_v_7
  - enterprise_linux_workstation_v_7
  - enterprise_linux_appstream_e4s_v_8_1
  - enterprise_linux_appstream_eus_v_8_2
  - enterprise_linux_appstream_eus_v_8_4
  - enterprise_linux_appstream_v_8
patched:
  - enterprise_linux_server_v_7
  - enterprise_linux_workstation_v_7
  - enterprise_linux_appstream_e4s_v_8_1
  - enterprise_linux_appstream_eus_v_8_2
  - enterprise_linux_appstream_eus_v_8_4
  - enterprise_linux_appstream_v_8
published: '2021-11-26'
updated: '2026-09-07'
sourceUpdated: '2026-09-07T16:51:02+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44227.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44227.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-44227'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2026862'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-44227'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-44227'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4913'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5081'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5080'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4915'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4916'
  - url: 'https://bugs.launchpad.net/mailman/+bug/1952384'
  - url: 'https://gitlab.com/mailman/mailman'
  - url: 'https://lists.debian.org/debian-lts-announce/2022/06/msg00011.html'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00757
epssPercentile: 0.53274
aliases:
  - GHSA-xq58-69h2-765m
  - PYSEC-2026-660
ecosystem: pip
ingestedAt: '2026-07-08T18:25:54.470Z'
---

## Overview

A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be used by an admin to perform an admin-level request, effectively bypassing the protection provided by CSRF tokens. A remote attacker with an account on the mailman system can use this flaw to perform a CSRF attack and perform operations on behalf of the victim admin.

## Vendor advisories

- **RHSA-2021:4913** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Workstation (v. 7) · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4913)
- **RHSA-2021:5081** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v. 8.1) · released 2021-12-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:5081)
- **RHSA-2021:5080** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 8.2) · released 2021-12-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:5080)
- **RHSA-2021:4915** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.4) · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4915)
- **RHSA-2021:4916** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4916)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44227.json)

**mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover** — rated Important by Red Hat. Released 2021-11-26, updated 2026-09-07.

Affected:

- Red Hat Enterprise Linux 6

Fixed:

- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- Red Hat Enterprise Linux AppStream EUS (v. 8.2)
- Red Hat Enterprise Linux AppStream EUS (v.8.4)
- Red Hat Enterprise Linux AppStream (v. 8)

No fix planned:

- Red Hat Enterprise Linux 6

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:4913
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:5081
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:5080

Workarounds / mitigations:

- Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

## Package advisory (CVE-2021-44227)

Affected packages:

- `mailman < 2.1.38`

Patched in:

- `mailman 2.1.38`

Source: https://osv.dev/vulnerability/GHSA-xq58-69h2-765m
