I have updated Zimbra Foss CVE Commits page to include 10.1.13 CVE commits.
I ask for community help so that the 10.0.18 commits (which should be similar to the 10.1.13 ones) are filled. Otherwise they will left blank.
Thank you.
Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)
- adrian.gibanel.btactic
- Outstanding Member

- Posts: 568
- Joined: Thu Jan 30, 2014 11:13 am
- Contact:
Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)
adrian.gibanel.btactic,
Much thanks for creating and updating this ever more important CVE page.
Unfortunately I have nothing to add to 10.0.18, but the final commit for 10.1.13 that's missing can be found here:
https://github.com/Zimbra/zm-mailbox/co ... d1bbf52d96
Added input validation and null checks in the PreAuthServlet to prevent internal error disclosure on malformed requests
Much thanks for creating and updating this ever more important CVE page.
Unfortunately I have nothing to add to 10.0.18, but the final commit for 10.1.13 that's missing can be found here:
https://github.com/Zimbra/zm-mailbox/co ... d1bbf52d96
Added input validation and null checks in the PreAuthServlet to prevent internal error disclosure on malformed requests
Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)
Zimbra 10.0 is EOL now, so maybe focus the effort on 10.1 only, or the latest release in general.
- adrian.gibanel.btactic
- Outstanding Member

- Posts: 568
- Joined: Thu Jan 30, 2014 11:13 am
- Contact:
Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)
Thank you for the catch! I updated the CVE page accordingly.zmcontrol wrote: ↑Thu Jan 08, 2026 3:14 pm adrian.gibanel.btactic,
Much thanks for creating and updating this ever more important CVE page.
But the final commit for 10.1.13 that's missing can be found here:
https://github.com/Zimbra/zm-mailbox/co ... d1bbf52d96
Added input validation and null checks in the PreAuthServlet to prevent internal error disclosure on malformed requests
- adrian.gibanel.btactic
- Outstanding Member

- Posts: 568
- Joined: Thu Jan 30, 2014 11:13 am
- Contact:
Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)
10.0.18 was supported recently.
After 10.0.18, yes, all the efforts will be centered on 10.1.x or newer versions.
- adrian.gibanel.btactic
- Outstanding Member

- Posts: 568
- Joined: Thu Jan 30, 2014 11:13 am
- Contact:
Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)
I have finally updated those CVE commits for 10.0.18.adrian.gibanel.btactic wrote: ↑Thu Jan 08, 2026 1:48 pm I ask for community help so that the 10.0.18 commits (which should be similar to the 10.1.13 ones) are filled. Otherwise they will left blank.
Unfortunately the CVE-2025-68645 commits for 10.0.18 are missing.
