Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY command will be accepted multiple times, with later invocations overriding earlier ones. The proxy protocol only supports one initial PROXY header; anything after that is considered part of the exchange between client and server, so the client is free to send further PROXY commands with whatever data it pleases. go-guerrilla will treat these as coming from the reverse proxy, allowing a client to spoof its IP address. This vulnerability is fixed in 1.6.7.
History

Wed, 28 Jan 2026 23:30:00 +0000


Wed, 28 Jan 2026 22:45:00 +0000


Wed, 02 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 22:15:00 +0000

Type Values Removed Values Added
Description Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY command will be accepted multiple times, with later invocations overriding earlier ones. The proxy protocol only supports one initial PROXY header; anything after that is considered part of the exchange between client and server, so the client is free to send further PROXY commands with whatever data it pleases. go-guerrilla will treat these as coming from the reverse proxy, allowing a client to spoof its IP address. This vulnerability is fixed in 1.6.7.
Title Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple times
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-28T22:27:22.773Z

Reserved: 2025-03-26T15:04:52.627Z

Link: CVE-2025-31135

cve-icon Vulnrichment

Updated: 2025-04-02T13:47:55.253Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-01T22:15:21.437

Modified: 2026-01-28T23:15:50.267

Link: CVE-2025-31135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.