Skip to content

Strict CRLF check in SMTP protocol #661

@hafeoz

Description

@hafeoz

The go-smtp package has released a new version, where strict CRLF check is performed to mitigate an zero-day attack against SMTP known as SMTP Smuggling. I think Maddy should probably update the dependency and (probably) release a new version with the updated dependency.

  • maddy version: all?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working.ready-for-releaseFeature is implemented and available for testing in dev branch. It will be included in the next rele

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions