lettre
a mailer library for Rust
Activity
- Latest release
- 1mo ago
- Total releases
- 65
- Cadence
- ~27 days
- Last 12 months
- 5
Reach
- Stars
- 2.2k
Details
- License
- MIT
- First release
- Oct 21, 2015
| Version | Released | |
|---|---|---|
0.11.23
patch
|
0.11.23
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.22
patch
|
0.11.22
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.21
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.21
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.20
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.20
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.19
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.19
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.18
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.18
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.17
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.17
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.16
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.16
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.15
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.15
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.14
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.14
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.13
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.13
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.11.12
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.12
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.11
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.11
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.10
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.10
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.9
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.9
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.8
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.8
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.11.7
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.7
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.6
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.6
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.5
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.5
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.4
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.4
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.3
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.3
patch
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
0.11.2
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.2
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.1
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.1
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.11.0
minor
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.11.0
minor
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.10.4
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.10.4
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.10.3
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.10.3
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.10.2
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.10.2
patch
Dependencies (43)
+ 35 more
Changelog
Compare changes
|
|
0.10.1
patch
1 CVE
CVE-2026-46428
GHSA-4pj9-g833-qx53
RUSTSEC-2026-0141
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
Network
Low
None
None
SummaryAn inverted-boolean bug in lettre's Detailsboring's
PoCSetup (any lettre version >= v0.10.1, built with the
ImpactWho is impacted: any lettre user who
Fixed in
0.11.22
References
Updated Jul 28, 2026 · Source: OSV.dev |
0.10.1
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.10.0
minor
|
0.10.0
minor
Dependencies (42)
+ 34 more
Changelog
Compare changes
|
|
0.10.0-rc.7
pre
|
0.10.0-rc.7
pre
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
0.10.0-rc.6
pre
|
0.10.0-rc.6
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.10.0-rc.5
pre
|
0.10.0-rc.5
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.10.0-rc.4
pre
|
0.10.0-rc.4
pre
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
0.10.0-rc.3
pre
|
0.10.0-rc.3
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.6
patch
|
0.9.6
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.10.0-rc.2
pre
|
0.10.0-rc.2
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.10.0-rc.1
pre
|
0.10.0-rc.1
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.10.0-beta.4
pre
|
0.10.0-beta.4
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.10.0-beta.3
pre
|
0.10.0-beta.3
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.10.0-beta.2
pre
|
0.10.0-beta.2
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.10.0-beta.1
pre
|
0.10.0-beta.1
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.10.0-alpha.5
pre
|
0.10.0-alpha.5
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.7.1
patch
1 CVE
CVE-2021-38189
GHSA-qc36-q22q-cjw3
RUSTSEC-2021-0069
Jul 12, 2021
SMTP command injection in lettre
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAffected versions of lettre allowed SMTP command injection through an attacker's controlled message body. The module for escaping lines starting with a period wouldn't catch a period that was placed after a double CRLF sequence, allowing the attacker to end the current message and write arbitrary SMTP commands after it. FixThe flaw is fixed by correctly handling consecutive CRLF sequences. ReferencesFixed in
0.9.6
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.7.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.4
patch
1 CVE
CVE-2021-38189
GHSA-qc36-q22q-cjw3
RUSTSEC-2021-0069
Jul 12, 2021
SMTP command injection in lettre
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAffected versions of lettre allowed SMTP command injection through an attacker's controlled message body. The module for escaping lines starting with a period wouldn't catch a period that was placed after a double CRLF sequence, allowing the attacker to end the current message and write arbitrary SMTP commands after it. FixThe flaw is fixed by correctly handling consecutive CRLF sequences. ReferencesFixed in
0.9.6
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.5
patch
1 CVE
CVE-2021-38189
GHSA-qc36-q22q-cjw3
RUSTSEC-2021-0069
Jul 12, 2021
SMTP command injection in lettre
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAffected versions of lettre allowed SMTP command injection through an attacker's controlled message body. The module for escaping lines starting with a period wouldn't catch a period that was placed after a double CRLF sequence, allowing the attacker to end the current message and write arbitrary SMTP commands after it. FixThe flaw is fixed by correctly handling consecutive CRLF sequences. ReferencesFixed in
0.9.6
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.9.5
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.10.0-alpha.4
pre
|
0.10.0-alpha.4
pre
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.10.0-alpha.3
pre
|
0.10.0-alpha.3
pre
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.6.3
patch
|
0.6.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.10.0-alpha.2
pre
|
0.10.0-alpha.2
pre
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.10.0-alpha.1
pre
|
0.10.0-alpha.1
pre
Dependencies (28)
+ 20 more
Changelog
Compare changes
|