VendorsAxllentmailpitany version
Vulnerabilities

Axllent Mailpit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-27808
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API
Published 2026-02-25 · Analyzed
8.6EPSS 0.006
CVE-2026-45711
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Published 2026-07-20 · Analyzed
8.2EPSS 0.004
CVE-2026-45713
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
Published 2026-07-20 · Analyzed
7.5EPSS 0.006
CVE-2026-23845
Mailpit Vulnerable to Server-Side Request Forgery (SSRF) via HTML Check API
Published 2026-01-19 · Analyzed
7.5EPSS 0.004
CVE-2026-22689
Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
Published 2026-01-10 · Analyzed
6.5EPSS 0.002
CVE-2026-45712
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Published 2026-07-20 · Analyzed
5.9EPSS 0.003
CVE-2026-21859
Mailpit Proxy Endpoint is Vulnerable to Server-Side Request Forgery (SSRF)
Published 2026-01-07 · Analyzed
5.8EPSS 0.008
CVE-2026-45709
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Published 2026-07-20 · Analyzed
5.8EPSS 0.003
CVE-2026-23829
Mailpit has SMTP Header Injection via Regex Bypass
Published 2026-01-18 · Analyzed
5.3EPSS 0.014
CVE-2026-48824
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Published 2026-07-20 · Analyzed
5.3EPSS 0.005