Server-Side Request Forgery in Mailpit Tool from Axllent
CVE-2026-27808

5.8MEDIUM

Key Information:

Vendor

Axllent

Status
Vendor
CVE Published:
25 February 2026

What is CVE-2026-27808?

A serious Server-Side Request Forgery (SSRF) vulnerability exists in Mailpit prior to version 1.29.2. This vulnerability allows attackers to exploit the Link Check API, where HTTP HEAD requests are sent to every URL found in an email without proper validation of the target hosts. Furthermore, the system does not filter private or internal IP addresses, enabling potential leakage of sensitive information. The threat is heightened due to the default configuration allowing remote exploitation without requiring user interaction. This vulnerability is part of ongoing security concerns that have led to multiple similar issues being fixed in previous versions. Upgrade to version 1.29.2 to ensure protection against these risks.

Affected Version(s)

mailpit < 1.29.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.