Server-Side Request Forgery Vulnerability in Mailpit Email Testing Tool
CVE-2026-45709

5.8MEDIUM

Key Information:

Vendor

Axllent

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-45709?

Mailpit, an email testing and API tool, is vulnerable to a server-side request forgery (SSRF) issue affecting versions prior to v1.30.0. The flaw allows attackers to manipulate the tool into making HTTP requests to internal resources. This can be exploited by sending an HTML email and then invoking the HTML check API, enabling a public site to redirect requests into the private network without being detected. The vulnerability persists due to inadequate IP allowlisting in the code for certain internal functions. To mitigate this risk, users should upgrade to Mailpit version 1.30.0, which includes an improved fix.

Affected Version(s)

mailpit >= 1.28.3, < 1.30.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.