PT-2026-61618 · Lettre · Lettre

CVE-2026-46428

·

Published

2026-05-14

·

Updated

2026-07-20

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions lettre versions 0.10.1 through 0.11.21
Description An inverted-boolean bug in the boring-tls integration silently disables TLS hostname verification for users employing the default strict configuration. This allows an on-path attacker with a chain-valid certificate for any domain to intercept SMTP submission, which may include message contents and PLAIN/LOGIN credentials. This issue specifically affects users who build the library with the boring-tls feature; other TLS backends such as native-tls and rustls are not impacted.
Recommendations Update to version 0.11.22.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46428
GHSA-4PJ9-G833-QX53
RUSTSEC-2026-0141

Affected Products

Lettre