Server-Side Request Forgery in Mailpit Tool from Axllent
CVE-2026-27808
5.8MEDIUM
What is CVE-2026-27808?
A serious Server-Side Request Forgery (SSRF) vulnerability exists in Mailpit prior to version 1.29.2. This vulnerability allows attackers to exploit the Link Check API, where HTTP HEAD requests are sent to every URL found in an email without proper validation of the target hosts. Furthermore, the system does not filter private or internal IP addresses, enabling potential leakage of sensitive information. The threat is heightened due to the default configuration allowing remote exploitation without requiring user interaction. This vulnerability is part of ongoing security concerns that have led to multiple similar issues being fixed in previous versions. Upgrade to version 1.29.2 to ensure protection against these risks.
Affected Version(s)
mailpit < 1.29.2
