Inverted Boolean Bug in Mailer Library for Rust by Lettre
CVE-2026-46428
9.1CRITICAL
What is CVE-2026-46428?
The Lettre mailer library for Rust has a vulnerability where an inverted-boolean issue in the boring-tls integration can lead to the silent disabling of TLS hostname verification in versions prior to 0.11.22. This flaw allows an on-path attacker to intercept SMTP submissions, potentially exposing sensitive user credentials and message contents to unauthorized parties. Versions using alternative TLS backends remain unaffected. To secure your application, users are urged to upgrade to version 0.11.22 or later.
Affected Version(s)
lettre >= 0.10.1, < 0.11.22
