Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59937

28
FAUCET Score

CVE-2025-59937 is a critical vulnerability in the go-mail library (versions 0.7.0 and below) that allows for ESMTP parameter smuggling or incorrect mail routing due to improper handling of mail.Address values in SMTP commands. This vulnerability affects applications using go-mail that accept arbitrary user input for sender or recipient addresses. The vulnerability has a CVSS score of 9.1 (CRITICAL), indicating a high-impact, easily exploitable flaw with no user interaction required. Successful exploitation could lead to unauthorized information disclosure or modification. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. The vendor has released a fix in version 0.7.1.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.7.1CPE matchmatch criteria
cpe:2.3:a:pebcak:go-mail:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 19th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/wneessen/go-mailFixed in: 0.7.1

Vendor Advisories (1)

goGHSA-wpwj-69cm-q9c5high

go-mail has insufficient address encoding when passing mail addresses to the SMTP client

Sep 29, 2025

References

github.com / wneessen/go-mail/commit/42e92cfe027be04aff72921adb0f72f11d517479
Patch
github.com / wneessen/go-mail/issues/495
ExploitIssue Tracking
github.com / wneessen/go-mail/pull/496
Issue TrackingPatch
github.com / wneessen/go-mail/security/advisories/GHSA-wpwj-69cm-q9c5
Vendor Advisory