Postfix is a widely deployed open-source mail transfer agent that serves as the backbone for email infrastructure across numerous organizations and cloud providers, making vulnerabilities in the software a concern across a large deployment footprint despite the narrow product scope. The recurring weakness classes affecting the vendor reflect the complexity of mail parsing and system interaction: symlink-following and file-access issues, information disclosure, input validation flaws, SQL injection, and memory-handling vulnerabilities recur across the codebase and warrant close attention from operators managing internet-facing mail infrastructure. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postfix over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1720MEDIUM The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not crea | May 13, 2011 | 6.8 | 34 | NO | NO |
CVE-2026-43964HIGH Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third n | May 4, 2026 | 7.5 | 33 | NO | NO |
CVE-2011-0411MEDIUM The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows m | Mar 16, 2011 | 6.8 | 31 | NO | NO |
CVE-2008-2936MEDIUM Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-ma | Aug 18, 2008 | 6.2 | 25 | NO | YES |
CVE-2017-10140HIGH Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berke | Apr 16, 2018 | 7.8 | 24 | NO | NO |
CVE-2012-0811MEDIUM Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter | Oct 1, 2014 | 6.5 | 23 | NO | NO |
CVE-2023-51764MEDIUM Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other optio | Dec 24, 2023 | 5.3 | 21 | NO | NO |
CVE-2020-12063MEDIUM A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf t | Apr 24, 2020 | 5.3 | 19 | NO | NO |
CVE-2009-2939MEDIUM The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users t | Sep 21, 2009 | 6.9 | 19 | NO | NO |
CVE-2008-4977MEDIUM postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and ( | Nov 6, 2008 | 6.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postfix.
Media articles that mention a CVE ID that affects a product developed by Postfix — matched by CVE ID, not by vendor name.