Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40606

19
FAUCET Score

CVE-2026-40606 is an authentication bypass vulnerability in mitmproxy versions 12.2.1 and below affecting the builtin LDAP proxy authentication mechanism. The flaw stems from improper sanitization of usernames when querying LDAP servers, allowing malicious clients to circumvent authentication controls. This vulnerability only impacts mitmproxy instances with the proxyauth option configured to use LDAP authentication, which is not enabled by default, significantly limiting exposure. The vulnerability carries a CVSS 3.1 score of 4.8 (Medium severity) with network-based attack vector, high attack complexity, and potential for low confidentiality and integrity impacts. The attack requires no user interaction or special privileges, but the high attack complexity requirement suggests additional conditions must be present for successful exploitation. The EPSS score of 0.00035 indicates this vulnerability poses minimal real-world exploitation risk relative to the broader CVE landscape. There is no evidence of active exploitation, and the vulnerability does not appear on the Known Exploited Vulnerabilities catalog or industry hotlists. The fix is readily available in mitmproxy version 12.2.2 and above. Organizations using mitmproxy with LDAP authentication should prioritize patching, though the default configuration posture and high attack complexity suggest this poses a low-urgency remediation priority for most users.

Impacted Technologies

VendorProductVersion(s)CPE
< 12.2.2CPE matchmatch criteria
cpe:2.3:a:mitmproxy:mitmproxy:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 0th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: mitmproxyFixed in: 12.2.2
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-527g-3w9m-29hvmedium

mitmproxy has an LDAP Injection

Apr 14, 2026

References

github.com / mitmproxy/mitmproxy/security/advisories/GHSA-527g-3w9m-29hv
Vendor Advisory