mailcow < 2026-03b reflects raw REQUEST_URI into JavaScript and href links on the login page, allowing attackers to inject parameters that break JS logic and enable phishing.
id: CVE-2026-40878
info:
name: Mailcow < 2026-03b - Href Link Injection
author: ritikchaddha
...