Security Research

CVE-2023-51766 SMTP Smuggling: Sneaking Forged Mail Past SPF and DMARC

#Vulnerability Analysis#Code Audit#Network Attack#Email Security
Copper-orange SMTP traffic being rerouted between two hosts

The outbound SMTP server treats <LF>.<CR><LF> as ordinary body content; the inbound server treats it as the DATA terminator. That interpretation gap lets an attacker smuggle arbitrary SMTP commands past the recipient, bypassing SPF/DKIM/DMARC and forging mail from gmx.net, web.de, Exchange Online and beyond.

Unlock to view this content.