Please update as soon as possible: SOGo v5.12.11

Author: purejavaCreated Sep 16, 2026Updated Sep 16, 2026
Labelsenhancement

Summary

See: https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.11

Motivation

Three major vulnerabilities have been reported and fixed in this version 5.12.11 or since the nightly of the 13th of September 2026: sogo_5.12.9.20260810.

Those vulnerabilities affect any previous SOGO version. Please update as soon as possible

CVE ID will be updated once they're created

  • 1 Password reset poisoning -> fixed
  • Several XSS injections with malicious mail or request -> fixed

Additional context

No response

Source: mailcow/mailcow-dockerized