CVE-2026-40606 is an authentication bypass vulnerability in mitmproxy versions 12.2.1 and below affecting the builtin LDAP proxy authentication mechanism. The flaw stems from improper sanitization of usernames when querying LDAP servers, allowing malicious clients to circumvent authentication controls. This vulnerability only impacts mitmproxy instances with the proxyauth option configured to use LDAP authentication, which is not enabled by default, significantly limiting exposure. The vulnerability carries a CVSS 3.1 score of 4.8 (Medium severity) with network-based attack vector, high attack complexity, and potential for low confidentiality and integrity impacts. The attack requires no user interaction or special privileges, but the high attack complexity requirement suggests additional conditions must be present for successful exploitation. The EPSS score of 0.00035 indicates this vulnerability poses minimal real-world exploitation risk relative to the broader CVE landscape. There is no evidence of active exploitation, and the vulnerability does not appear on the Known Exploited Vulnerabilities catalog or industry hotlists. The fix is readily available in mitmproxy version 12.2.2 and above. Organizations using mitmproxy with LDAP authentication should prioritize patching, though the default configuration posture and high attack complexity suggest this poses a low-urgency remediation priority for most users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.2.2CPE matchmatch criteria | cpe:2.3:a:mitmproxy:mitmproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.