← Vulnerability feed

Vulnerability record · CVE-2026-45712 · published 20 July 2026

CVE-2026-45712: Axllent mailpit race condition vulnerability

Axllent · Mailpit

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the unsynchronized read coincides with a synchronized write, Go's runtime raises fatal error: concurrent map read and map write — a runtime.throw that is not recoverable by http.Server's handler-panic recover. The whole Mailpit process exits, taking the SMTP, POP3 and HTTP listeners down with it. Version 1.30.0 contains a patch.

5.9 CVSS 3.1 Medium EPSS 0.34% · top 75.5% CWE-362 · Race conditionCWE-770 · Allocation without limits
5.9CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
28 Jul 2026Last modified by NVD

Description

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the unsynchronized read coincides with a synchronized write, Go's runtime raises fatal error: concurrent map read and map write — a runtime.throw that is not recoverable by http.Server's handler-panic recover. The whole Mailpit process exits, taking the SMTP, POP3 and HTTP listeners down with it. Version 1.30.0 contains a patch.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45712 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-27808Axllent mailpit server-side request forgery (ssrf) vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is vulnerable …EPSS 0.56%8.2CVE-2026-45711Axllent mailpit path traversal vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads …EPSS 0.39%7.5CVE-2026-45713Axllent mailpit uncontrolled resource consumption vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that control…EPSS 0.61%7.5CVE-2026-23845Axllent mailpit server-side request forgery (ssrf) vulnerabilityMailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check…EPSS 0.44%6.5CVE-2026-22689Axllent mailpit vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections fr…EPSS 0.24%5.8CVE-2026-45709Axllent mailpit server-side request forgery (ssrf) vulnerabilityMailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTM…EPSS 0.32%5.3CVE-2026-48824Axllent mailpit allocation without limits vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a de…EPSS 0.54%5.3CVE-2026-23829Axllent mailpit vulnerabilityMailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an i…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-45712), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.