[ixpmanager-announce] [RELEASE] V7.3.1 - Security Updates (severity: critical), bug fix only

Nick Hilliard (INEX) nick at inex.ie
Wed Jul 8 16:12:28 IST 2026


INEX is pleased to announce the availability of IXP Manager v7.3.1. This 
is a security release following a responsible disclosure. The issue 
reported has been assigned severity critical.

⚠️ All IXP Manager users should upgrade to v7.3.1.

Security Policy & EU CRA Alignment

As IXP Manager powers critical internet infrastructure globally, 
security is core to our processes, and this is the fifth successive 
release primarily focused on security. We accept responsibly-disclosed 
security vulnerability reports and we have also used third-party 
reporting as a catalyst to perform proactive internal audits of our 
codebase, leading to the discovery and mitigation of additional 
vulnerabilities.

Also, with the European Union’s Cyber Resilience Act mandatory reporting 
requirements taking effect this September, INEX acknowledges its legal 
role as an Open-Source Software Steward. These obligations are reflected 
in our Security Policy 
<https://github.com/inex/IXP-Manager/security/policy>.

Security Advisory: Vulnerabilities Resolved in v7.3.1

Impact: Critical (RCE via authenticated access)

  * Remote Code Execution (CVE pending) (CVSS 3.1 Base Severity: 9.9) -
    a confirmed vulnerability allows an authenticated,
    non-administrative user to execute code on the IXP Manager hosting
    environment. This was responsibly disclosed by 9Bakabaka.

Remediation: This issue is addressed in the v7.3.1 release. Please 
upgrade to v7.3.1 as soon as possible.


Kind regards,

Nick Hilliard
INEX

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://www.inex.ie/pipermail/ixpmanager-announce/attachments/20260708/66cf7746/attachment.htm>


More information about the ixpmanager-announce mailing list