
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40606 is an LDAP Injection vulnerability in mitmproxy's built-in LDAP proxy authentication that allows a malicious client to bypass authentication by crafting a specially formed username. It affects mitmproxy versions 12.2.1 and below; only instances configured with the proxyauth option using LDAP are impacted, and this option is not enabled by default. The vulnerability was initially reported on 2025-12-08, verified on 2025-12-09, and publicly disclosed with a patch on 2026-04-12. It carries a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is improper neutralization of special elements used in LDAP queries (CWE-90 / LDAP Injection, CAPEC-136). When mitmproxy's built-in proxy authentication is configured to use LDAP, the username supplied by a connecting client is incorporated into an LDAP query without adequate sanitization. An attacker can inject LDAP special characters (e.g., *, (, ), \, NUL) into the username field to manipulate the query logic and cause the LDAP server to return a successful authentication result for an otherwise unauthorized user. Exploitation requires that the target mitmproxy instance has the proxyauth option explicitly configured with an LDAP backend, which is a non-default configuration (GitHub Advisory).
Successful exploitation allows an unauthenticated or unauthorized client to bypass LDAP-based proxy authentication on affected mitmproxy instances, gaining unauthorized access to the proxy and any traffic routed through it. This can expose proxied HTTP/TLS traffic to interception or manipulation, undermine security controls that rely on LDAP authentication, and potentially allow attackers to use the proxy as a pivot point. Confidentiality and integrity impacts are rated Low; there is no availability impact (GitHub Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.035%, reflecting low near-term exploitation probability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement that the target must have LDAP-based proxyauth explicitly configured, raising the effective attack complexity (GitHub Advisory, Feedly).
proxyauth configuration.Proxy-Authenticate header requiring credentials.*)(uid=*))(|(uid=* to cause the LDAP query to match any user.Proxy-Authorization header of an HTTP CONNECT or standard proxy request.CONNECT or standard proxy requests) containing usernames with LDAP special characters such as *, (, ), \, or null bytes in the Proxy-Authorization header.Upgrade mitmproxy to version 12.2.2 or later, which contains the fix for this vulnerability (GitHub Advisory). If immediate patching is not feasible, disable the proxyauth LDAP option until the upgrade can be completed, or restrict network access to the proxy port to trusted clients only. Review mitmproxy access logs for suspicious authentication attempts that may indicate exploitation. Note that instances not using the proxyauth option with LDAP are not affected.
The vulnerability was responsibly disclosed by researcher Yue (Knox) Liu (@yueyueL) to the mitmproxy team, who coordinated a patch release approximately four months after the initial report. The mitmproxy maintainer (mhils) published the advisory alongside the 12.2.2 patch release on 2026-04-12. No significant broader media coverage or notable community controversy has been observed, consistent with the moderate severity rating and non-default affected configuration (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."