📦 Mailpit

by Axllent

🔍 What is Mailpit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-27808

MEDIUM CVSS 5.8 Feb 26, 2026

Mailpit versions before 1.29.2 contain a Server-Side Request Forgery (SSRF) vulnerability in the Link Check API that allows attackers to make the server send HTTP HEAD requests to arbitrary URLs, incl...

CVE-2026-23845

MEDIUM CVSS 5.8 Jan 19, 2026

Mailpit versions before 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) through the HTML Check feature. When analyzing HTML emails, the system automatically downloads CSS files from extern...

CVE-2026-22689

MEDIUM CVSS 6.5 Jan 10, 2026

Mailpit versions before 1.28.2 have a Cross-Site WebSocket Hijacking vulnerability due to missing Origin header validation. This allows malicious websites to connect to a developer's local Mailpit ins...

CVE-2026-21859

MEDIUM CVSS 5.8 Jan 8, 2026

Mailpit versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint that allows attackers to make HTTP GET requests to internal network resources. Attacker...