[ixpmanager-announce] [RELEASE] V7.3.1 - Security Updates (severity: critical), bug fix only
Nick Hilliard (INEX)
nick at inex.ie
Wed Jul 8 16:12:28 IST 2026
INEX is pleased to announce the availability of IXP Manager v7.3.1. This
is a security release following a responsible disclosure. The issue
reported has been assigned severity critical.
⚠️ All IXP Manager users should upgrade to v7.3.1.
Security Policy & EU CRA Alignment
As IXP Manager powers critical internet infrastructure globally,
security is core to our processes, and this is the fifth successive
release primarily focused on security. We accept responsibly-disclosed
security vulnerability reports and we have also used third-party
reporting as a catalyst to perform proactive internal audits of our
codebase, leading to the discovery and mitigation of additional
vulnerabilities.
Also, with the European Union’s Cyber Resilience Act mandatory reporting
requirements taking effect this September, INEX acknowledges its legal
role as an Open-Source Software Steward. These obligations are reflected
in our Security Policy
<https://github.com/inex/IXP-Manager/security/policy>.
Security Advisory: Vulnerabilities Resolved in v7.3.1
Impact: Critical (RCE via authenticated access)
* Remote Code Execution (CVE pending) (CVSS 3.1 Base Severity: 9.9) -
a confirmed vulnerability allows an authenticated,
non-administrative user to execute code on the IXP Manager hosting
environment. This was responsibly disclosed by 9Bakabaka.
Remediation: This issue is addressed in the v7.3.1 release. Please
upgrade to v7.3.1 as soon as possible.
Kind regards,
Nick Hilliard
INEX
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://www.inex.ie/pipermail/ixpmanager-announce/attachments/20260708/66cf7746/attachment.htm>
More information about the ixpmanager-announce
mailing list