← Vulnerability feed

Vulnerability record · CVE-2026-23829 · published 19 January 2026

CVE-2026-23829: Axllent mailpit vulnerability

Axllent · Mailpit

Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class. Version 1.28.3 fixes this issue.

5.3 CVSS 3.1 Medium EPSS 1.4% · top 28.2% CWE-93 · CWE-93CWE-150 · CWE-150
5.3CVSS 3.1 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class. Version 1.28.3 fixes this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23829 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-27808Axllent mailpit server-side request forgery (ssrf) vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is vulnerable …EPSS 0.56%8.2CVE-2026-45711Axllent mailpit path traversal vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads …EPSS 0.39%7.5CVE-2026-45713Axllent mailpit uncontrolled resource consumption vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that control…EPSS 0.61%7.5CVE-2026-23845Axllent mailpit server-side request forgery (ssrf) vulnerabilityMailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check…EPSS 0.44%6.5CVE-2026-22689Axllent mailpit vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections fr…EPSS 0.24%5.9CVE-2026-45712Axllent mailpit race condition vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-leve…EPSS 0.34%5.8CVE-2026-45709Axllent mailpit server-side request forgery (ssrf) vulnerabilityMailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTM…EPSS 0.32%5.3CVE-2026-48824Axllent mailpit allocation without limits vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a de…EPSS 0.54%

Source: NIST National Vulnerability Database (record CVE-2026-23829), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.