Server-Side Request Forgery Vulnerability in Mailpit Email Testing Tool
CVE-2026-45709
5.8MEDIUM
What is CVE-2026-45709?
Mailpit, an email testing and API tool, is vulnerable to a server-side request forgery (SSRF) issue affecting versions prior to v1.30.0. The flaw allows attackers to manipulate the tool into making HTTP requests to internal resources. This can be exploited by sending an HTML email and then invoking the HTML check API, enabling a public site to redirect requests into the private network without being detected. The vulnerability persists due to inadequate IP allowlisting in the code for certain internal functions. To mitigate this risk, users should upgrade to Mailpit version 1.30.0, which includes an improved fix.
Affected Version(s)
mailpit >= 1.28.3, < 1.30.0
