Server-Side Request Forgery Vulnerability in Mailpit Email Testing Tool
CVE-2026-23845
5.8MEDIUM
What is CVE-2026-23845?
Mailpit, an email testing tool and API predominantly used by developers, suffers from a Server-Side Request Forgery (SSRF) vulnerability. This issue arises from the HTML Check feature, where the function inlineRemoteCSS() improperly fetches CSS files from external <link rel="stylesheet" href="..."> tags during the HTML email analysis. This behavior can be exploited to make unauthorized requests to internal or external services. The vulnerability affects all versions of Mailpit before 1.28.3, and it has been addressed in this release. Users are strongly encouraged to update their installations to mitigate potential security risks.
Affected Version(s)
mailpit < 1.28.3
