Executive brief
Sagredo qmail is a modern distribution of the qmail mail server. A vulnerability in its TLS error handling allows an attacker to execute malicious commands on the mail server by sending an email from a specially configured domain. This could lead to a full system compromise or unauthorized access to email data.
Technical details
A command injection vulnerability exists in qmail-remote.c within the tls_quit() function. When the 'notlshosts_auto' feature is enabled, qmail-remote attempts to record hosts with failed TLS handshakes by executing a shell command via popen(). The command is constructed using sprintf() with the remote hostname (partner_fqdn) wrapped in single quotes. However, an attacker can bypass this by including single quotes and shell metacharacters (like backticks) in a DNS MX record. Because glibc's dn_expand() does not escape these characters, they are passed directly to the shell. An attacker who controls the DNS for a domain can achieve remote code execution as the qmailr user when the victim server attempts to deliver mail to that domain. This issue is fixed in version 2026.04.07.
Affected products
- sagredo-dev qmail v2024.10.26 through v2026.04.02
Timeline
- 2026-04-07: patched: Fixed in version v2026.04.07 via commit 749f607
- 2026-04-16: disclosed: Public disclosure and CVE assignment
- 2026-04-16: advisory
References
- https://blog.calif.io/p/we-asked-claude-to-audit-sagredos
- https://github.com/califio/publications/tree/main/MADBugs/qmail
- https://github.com/sagredo-dev/qmail/commit/749f607f6885e3d01b36f2647d7a1db88f1ef741
- https://github.com/sagredo-dev/qmail/pull/42
- https://github.com/sagredo-dev/qmail/releases/tag/v2026.04.07
- http://www.openwall.com/lists/oss-security/2026/04/18/5