PT-2026-61618 · Lettre · Lettre
CVE-2026-46428
·
Published
2026-05-14
·
Updated
2026-07-20
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
lettre versions 0.10.1 through 0.11.21
Description
An inverted-boolean bug in the
boring-tls integration silently disables TLS hostname verification for users employing the default strict configuration. This allows an on-path attacker with a chain-valid certificate for any domain to intercept SMTP submission, which may include message contents and PLAIN/LOGIN credentials. This issue specifically affects users who build the library with the boring-tls feature; other TLS backends such as native-tls and rustls are not impacted.Recommendations
Update to version 0.11.22.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lettre