CVE-2016-7143: Charybdis Project Charybdis

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

Affected products

Published 2016-09-21. Last modified 2026-06-17.