Please update as soon as possible: SOGo v5.12.11
Author: purejavaCreated Sep 16, 2026Updated Sep 16, 2026
Labelsenhancement
Summary
See: https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.11
Motivation
Three major vulnerabilities have been reported and fixed in this version 5.12.11 or since the nightly of the 13th of September 2026: sogo_5.12.9.20260810.
Those vulnerabilities affect any previous SOGO version. Please update as soon as possible
CVE ID will be updated once they're created
- 1 Password reset poisoning -> fixed
- Several XSS injections with malicious mail or request -> fixed
Additional context
No response
Source: mailcow/mailcow-dockerized