Apache disclosed CVE-2026-41873, a critical flaw in the retired Lua implementation of Apache Pony Mail that allows unauthenticated administrator account takeover. STAR Labs reported that a CRLF injection bug in email.lua can be abused for HTTP request smuggling to Pony Mail’s backend Elasticsearch service, giving attackers a path to compromise any account, including admin users. Apache said all versions of the Lua implementation are affected, assigned the issue a critical severity, and confirmed that no patch will be released because the Lua codebase is retired and unsupported.
STAR Labs also detailed a separate blind SSRF issue in the unreleased Python implementation, Pony Mail Foal, where a user-controlled oauth_token value could make the server send crafted requests to attacker-controlled or internal URLs. The researchers showed that the flaw could be used against an internal Elasticsearch instance to infer and extract valid session identifiers, enabling authenticated user impersonation. Apache stated that Foal is not affected by CVE-2026-41873, but STAR Labs said the SSRF issue in Foal was patched by removing client-side exposure of OAuth URLs and blocking server-side use of user-supplied token exchange URLs; organizations still running the Lua implementation were advised to migrate or restrict access to trusted users only.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
STAR Labs publicly disclosed that the retired Lua implementation of Apache Pony Mail contains a CRLF injection leading to HTTP request smuggling and full account takeover, and that Pony Mail Foal had a blind SSRF issue enabling session inference against internal Elasticsearch. The advisory also stated that the Foal issue had been patched, while the Lua implementation remained vulnerable with no fix planned.
The National Vulnerability Database added its initial analysis for CVE-2026-41873 and assigned a critical CVSS v3.1 score on April 28, 2026. The entry described the flaw as affecting the retired Lua implementation and noted that Pony Mail Foal is not affected by this CVE.
Apache disclosed CVE-2026-41873, a critical HTTP request smuggling flaw affecting all versions of the retired Lua implementation of Pony Mail that can lead to administrator account takeover. Apache said the Lua project is unsupported, no fix will be released, and users should migrate or restrict access to trusted users.
Apache patched the Pony Mail Foal blind SSRF vulnerability by removing client-side exposure of OAuth URLs and stopping the server from accepting user-supplied token exchange URLs. This addressed the Foal issue described by STAR Labs, while the retired Lua implementation remained unfixed.
STAR Labs published technical details on two Apache-related vulnerabilities that reportedly did not receive CVE assignments: a blind SSRF in Pony Mail Foal's OAuth2 handling and an RCE issue in whimsy.apache.org's ruby2js.cgi. The write-up described successful session extraction and impersonation via internal Elasticsearch access, as well as arbitrary Ruby code execution and secret exfiltration on whimsy.apache.org.
According to STAR Labs, its disclosure process with the Apache Security Team for the Pony Mail issues began in July 2024. The process covered vulnerabilities affecting both the retired Lua implementation and the Foal Python implementation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecvefeed.io
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.