PT-2026-3488 · Mailpit · Mailpit

·

CVE-2026-23845

·

Published

2026-01-19

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mailpit versions prior to 1.28.3
Description Mailpit, an email testing tool and API for developers, contains a Server-Side Request Forgery (SSRF) issue. This flaw is related to the HTML Check CSS Download functionality, specifically within the HTML Check feature accessible via the /api/v1/message/{ID}/html-check API endpoint. The inlineRemoteCSS() function automatically downloads CSS files from external sources specified in <link rel="stylesheet" href="..."> tags during HTML analysis. This process can be exploited to trigger requests to unintended locations.
Recommendations Update to Mailpit version 1.28.3 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23845
GHSA-6JXM-FV7W-RW5J
GO-2026-4345
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0403-1

Affected Products

Mailpit