github.com/axllent/mailpit
An email and SMTP testing tool with API for developers
Activity
- Latest release
- 1w ago
- Total releases
- 22
- Cadence
- ~11 days
- Last 12 months
- 22
Reach
- Stars
- 10.3k
Details
- First release
- Jan 06, 2026
| Version | Released | |
|---|---|---|
v1.31.1
patch
|
v1.31.1
patch
Dependencies (23)
+ 15 more |
|
v1.31.0
minor
|
v1.31.0
minor
Dependencies (23)
+ 15 more |
|
v1.30.7
patch
|
v1.30.7
patch
Dependencies (23)
+ 15 more |
|
v1.30.6
patch
|
v1.30.6
patch
Dependencies (23)
+ 15 more |
|
v1.30.5
patch
1 CVE
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev |
v1.30.5
patch
Dependencies (23)
+ 15 more |
|
v1.30.4
patch
2 CVEs
CVE-2026-67447
GO-2026-6272
GHSA-r553-m4fv-5v97
Aug 25, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Fixed in
1.30.5
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev |
v1.30.4
patch
Dependencies (23)
+ 15 more |
|
v1.30.3
patch
4 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67447
GO-2026-6272
GHSA-r553-m4fv-5v97
Aug 25, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Fixed in
1.30.5
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev |
v1.30.3
patch
Dependencies (23)
+ 15 more |
|
v1.30.2
patch
4 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67447
GO-2026-6272
GHSA-r553-m4fv-5v97
Aug 25, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Fixed in
1.30.5
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev |
v1.30.2
patch
Dependencies (23)
+ 15 more |
|
v1.30.1
patch
5 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67447
GO-2026-6272
GHSA-r553-m4fv-5v97
Aug 25, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Fixed in
1.30.5
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.1
patch
Dependencies (23)
+ 15 more |
|
v1.30.0
minor
6 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67447
GO-2026-6272
GHSA-r553-m4fv-5v97
Aug 25, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit Fixed in
1.30.5
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.0
minor
Dependencies (23)
+ 15 more |
|
v1.29.7
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.7
patch
Dependencies (27)
+ 19 more |
|
v1.29.6
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.6
patch
Dependencies (27)
+ 19 more |
|
v1.29.5
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.5
patch
Dependencies (27)
+ 19 more |
|
v1.29.4
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.4
patch
Dependencies (27)
+ 19 more |
|
v1.29.3
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.3
patch
Dependencies (27)
+ 19 more |
|
v1.29.2
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.2
patch
Dependencies (27)
+ 19 more |
|
v1.29.1
patch
10 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27808
GO-2026-4558
GHSA-mpf7-p9x7-96r3
Feb 27, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Fixed in
1.29.2
References Updated Mar 09, 2026 · Source: OSV.dev |
v1.29.1
patch
Dependencies (27)
+ 19 more |
|
v1.29.0
minor
10 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67448
GO-2026-6271
GHSA-8r62-w5wh-fc5m
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit Fixed in
1.30.6
References Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27808
GO-2026-4558
GHSA-mpf7-p9x7-96r3
Feb 27, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Fixed in
1.29.2
References Updated Mar 09, 2026 · Source: OSV.dev |
v1.29.0
minor
Dependencies (27)
+ 19 more |
|
v1.28.4
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27808
GO-2026-4558
GHSA-mpf7-p9x7-96r3
Feb 27, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Fixed in
1.29.2
References Updated Mar 09, 2026 · Source: OSV.dev |
v1.28.4
patch
Dependencies (27)
+ 19 more |
|
v1.28.3
patch
9 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45709
GO-2026-5446
GHSA-j3fj-qppj-fmmc
Jun 25, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer in github.com/axllent/mailpit Fixed in
1.30.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27808
GO-2026-4558
GHSA-mpf7-p9x7-96r3
Feb 27, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Fixed in
1.29.2
References Updated Mar 09, 2026 · Source: OSV.dev |
v1.28.3
patch
Dependencies (27)
+ 19 more |
|
v1.28.2
patch
10 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27808
GO-2026-4558
GHSA-mpf7-p9x7-96r3
Feb 27, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Fixed in
1.29.2
References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-23829
GO-2026-4333
GHSA-54wq-72mp-cq7c
Feb 03, 2026
Mailpit has an SMTP Header Injection via Regex Bypass in github.com/axllent/mailpit Mailpit has an SMTP Header Injection via Regex Bypass in github.com/axllent/mailpit Fixed in
1.28.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-23845
GO-2026-4345
GHSA-6jxm-fv7w-rw5j
Feb 03, 2026
Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API in github.com/axllent/mailpit Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API in github.com/axllent/mailpit Fixed in
1.28.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.28.2
patch
Dependencies (27)
+ 19 more |
|
v1.28.1
initial
11 CVEs
CVE-2026-67446
GO-2026-6359
GHSA-75mr-qw9x-3r39
Sep 10, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67445
GO-2026-6363
GHSA-w878-pj84-3j5v
Sep 10, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit Fixed in
1.30.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48824
GO-2026-5868
GHSA-28pq-6qxg-wg5r
Jul 07, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) in github.com/axllent/mailpit Fixed in
1.30.1
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45712
GO-2026-5689
GHSA-w4vj-r5pg-3722
Jun 25, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55187
GO-2026-5688
GHSA-w4mc-hhc6-xp28
Jun 25, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms in github.com/axllent/mailpit Fixed in
1.30.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45711
GO-2026-5599
GHSA-qx5x-85p8-vg4j
Jun 25, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45713
GO-2026-5376
GHSA-fpxj-m5q8-fphw
Jun 25, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes in github.com/axllent/mailpit Fixed in
1.30.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27808
GO-2026-4558
GHSA-mpf7-p9x7-96r3
Feb 27, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API in github.com/axllent/mailpit Fixed in
1.29.2
References Updated Mar 09, 2026 · Source: OSV.dev
CVE-2026-23829
GO-2026-4333
GHSA-54wq-72mp-cq7c
Feb 03, 2026
Mailpit has an SMTP Header Injection via Regex Bypass in github.com/axllent/mailpit Mailpit has an SMTP Header Injection via Regex Bypass in github.com/axllent/mailpit Fixed in
1.28.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-23845
GO-2026-4345
GHSA-6jxm-fv7w-rw5j
Feb 03, 2026
Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API in github.com/axllent/mailpit Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API in github.com/axllent/mailpit Fixed in
1.28.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22689
GO-2026-4310
GHSA-524m-q5m7-79mm
Jan 23, 2026
Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails in github.com/axllent/mailpit Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails in github.com/axllent/mailpit. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/axllent/mailpit before v0.0.0-20260110031614. Fixed in
1.28.2
References Updated Jan 23, 2026 · Source: OSV.dev |
v1.28.1
initial
Dependencies (27)
+ 19 more |