PT-2026-3488 · Mailpit · Mailpit

Mdisec

·

Published

2026-01-19

·

Updated

2026-02-26

·

CVE-2026-23845

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mailpit versions prior to 1.28.3
Description Mailpit, an email testing tool and API for developers, contains a Server-Side Request Forgery (SSRF) issue. This flaw is related to the HTML Check CSS Download functionality, specifically within the HTML Check feature accessible via the /api/v1/message/{ID}/html-check API endpoint. The inlineRemoteCSS() function automatically downloads CSS files from external sources specified in <link rel="stylesheet" href="..."> tags during HTML analysis. This process can be exploited to trigger requests to unintended locations.
Recommendations Update to Mailpit version 1.28.3 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-23845
GHSA-6JXM-FV7W-RW5J
GO-2026-4345
SUSE-SU-2026:0403-1

Affected Products

Mailpit