Back to Database
Status published
Medium
CVE-2025-43921
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows...
Vulnerability Description
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-43921
Credits & Attribution
No credits recorded in the NVD database.
References
More from GNU
View All →CVE-2025-8746
GNU libopts __strstr_sse2 memory corruption
Medium
4.8
CVE-2025-8736
GNU cflow Lexer c.c yylex buffer overflow
Medium
4.8
CVE-2025-8735
GNU cflow Lexer c.c yylex null pointer dereference
Medium
4.8
CVE-2025-8225
GNU Binutils DWARF Section dwarf.c process_debug_info memory leak
Medium
4.8
CVE-2025-8224
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Medium
4.8
Affected Vendor
Affected Software
Mailman
Vulnerable Versions:
2.1.39
Timeline
Official Publish:
April 20th, 2025
Last Modified:
April 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N