PT-2026-3406 · Mailpit · Mailpit

Omarkurt

·

Published

2026-01-18

·

Updated

2026-03-13

·

CVE-2026-23829

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mailpit versions prior to 1.28
Description Mailpit, an email testing tool and API for developers, has a header injection issue in its SMTP server. This is due to a flawed regular expression used to validate RCPT TO and MAIL FROM addresses, failing to exclude carriage return characters (r) and newline characters ( ) within a character class. An attacker can inject arbitrary SMTP headers or corrupt existing ones by including these characters in the email address. The insufficient filtering of control characters allows for the manipulation of SMTP headers.
Recommendations Update to version 1.28 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-23829
GHSA-54WQ-72MP-CQ7C
GO-2026-4333
SUSE-SU-2026:0403-1

Affected Products

Mailpit