github.com/axllent/mailpit
Go10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/axllent/mailpitpage 1 of 1
- CVE-2026-21859MEDIUMCVSS 5.8EG 5.8✓ Fixed in 1.28.12026-01-08
Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint, allowing attackers to make requests to internal network resources. The /prox…
- CVE-2026-22689MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.28.22026-01-10
Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections from any origin. This lack of Origin header validation introduces a Cross-Site WebSocket Hij…
- CVE-2026-23829MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.28.32026-01-19
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An at…
- CVE-2026-23845MEDIUMCVSS 5.8EG 5.8✓ Fixed in 1.28.32026-01-19
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to a…
- CVE-2026-45709MEDIUMCVSS 5.8EG 5.8✓ Fixed in 1.30.02026-05-19
Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::download…
- CVE-2026-45711MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.30.02026-05-19
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads every message from a remote Mailpit instance and writes each one as <id>.eml inside the us…
- CVE-2026-45712MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.30.02026-05-19
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex w…
- CVE-2026-45713HIGHCVSS 7.5EG 7.5✓ Fixed in 1.30.02026-05-19
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside …
- CVE-2026-48824MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.30.12026-07-01
Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to prevent DoS via unlimited SMTP DATA and /api/v1/send body sizes") …
- CVE-2026-55187MEDIUMCVSS 5.8EG 5.8✓ Fixed in 1.30.22026-06-19
Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard library classifica…
Check whether github.com/axllent/mailpit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/axllent/mailpit CVEs against the assets you own.
Start Free Scan →