CVE-2025-53909·Docker vulnerability
mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts. The issue requires admin-level access to mailcow UI to configure templates, which are automatically rendered during normal system operation. Version 2025-07 contains a patch for the issue.
- Severity
- critical
- Software
- Docker
- Fixed in
- 2025-07
- Published
- 2025-07-17
Affected versions
Until: 2025-07
Fixed in: 2025-07
How to fix this CVE
Update Docker to version 2025-07 or later to patch a Server-Side Template Injection vulnerability in mailcow's notification template system. This vulnerability allows administrators with UI access to inject malicious template expressions that execute during quota and quarantine alert generation. Immediate patching is critical for environments running mailcow on Docker, as template rendering occurs automatically during normal operations.
sudo dnf update docker-ceDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Web Application Firewall rules should detect and block requests containing template syntax patterns (e.g., `{{`, `{%`, `${`) in notification template parameters and admin configuration endpoints. Rate-limit POST requests to `/admin/` endpoints handling template uploads or modifications to reduce brute-force attempts by unauthorized users.How to check if you are affected
- Run `docker --version` to check your current Docker version; versions prior to 2025-07 are vulnerable
- Verify if mailcow is deployed on this Docker instance by checking for mailcow containers: `docker ps --filter 'name=mailcow' --format '{{.Names}}'`
- Review mailcow notification template configurations in the admin UI or check the mailcow-dockerized configuration directory for custom template files
- After patching, confirm the update with `docker --version` and restart mailcow containers: `docker-compose -f /path/to/mailcow/docker-compose.yml restart`
FAQ
What is CVE-2025-53909?
CVE-2025-53909 is a Server-Side Template Injection (SSTI) vulnerability in mailcow's notification template rendering engine that allows authenticated administrators to inject malicious template code. The injected expressions are executed when the system automatically generates quota and quarantine alert notifications.
Is CVE-2025-53909 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available. However, the critical CVSS score of 9.1 warrants immediate patching.
What versions of Docker are affected by CVE-2025-53909?
All versions of mailcow-dockerized prior to 2025-07 are affected. This impacts Docker deployments running vulnerable mailcow releases.
How do I check if my server is vulnerable to CVE-2025-53909?
Run `docker ps -a` to list containers, identify mailcow instances, then check the mailcow version by inspecting logs: `docker logs mailcow-container-name 2>&1 | grep -i version`. Compare against the fixed version 2025-07.
Does Defensia detect CVE-2025-53909?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-53909 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-53909. Free for 1 server.
Get started free