PT-2026-2106 · Mailpit · Mailpit

Omarkurt

·

Published

2026-01-06

·

Updated

2026-03-27

·

CVE-2026-21859

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mailpit versions 1.28.0 and below
Description Mailpit is an email testing tool and API for developers. A Server-Side Request Forgery (SSRF) exists in the /proxy endpoint, allowing attackers to make requests to internal network resources. The /proxy endpoint validates http:// and https:// schemes but does not block internal IP addresses, enabling access to internal services and APIs. This is limited to HTTP GET requests with minimal headers.
Recommendations Update Mailpit to version 1.28.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-21859
GHSA-8V65-47JX-7MFR
GO-2026-4284
SUSE-SU-2026:0142-1

Affected Products

Mailpit