Loading
HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Use CWE-644, Icewarp vendor hub and Mail Server product page to widen CVE-2025-40631 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-39699, CVE-2020-14066 and CVE-2020-14065 for nearby disclosures in the same product family.