Executive brief
Go-Guerrilla is an email server toolkit. A vulnerability in its handling of the PROXY protocol allows an attacker to send multiple identity headers, which can be used to spoof the sender's IP address. This could allow malicious actors to bypass IP-based security filters or logging, potentially leading to unauthorized email delivery or obscured activity.
Technical details
Go-Guerrilla SMTP Daemon incorrectly processes the PROXY protocol by allowing the PROXY command to be sent multiple times during a session. When the 'ProxyOn' configuration is enabled, the server accepts subsequent PROXY headers and allows them to override the initial connection data. Because the proxy protocol is intended to be a single initial header, an attacker can send additional PROXY commands containing arbitrary IP addresses. This results in the 'RemoteIP' field being overwritten with spoofed data. The issue is fixed in version 1.6.7.
Affected products
- phires go-guerrilla < 1.6.7
Timeline
- 2025-04-01: disclosed
- 2025-04-01: advisory
- 1.6.7: patched