Inverted Boolean Bug in Mailer Library for Rust by Lettre
CVE-2026-46428

9.1CRITICAL

Key Information:

Vendor

Lettre

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-46428?

The Lettre mailer library for Rust has a vulnerability where an inverted-boolean issue in the boring-tls integration can lead to the silent disabling of TLS hostname verification in versions prior to 0.11.22. This flaw allows an on-path attacker to intercept SMTP submissions, potentially exposing sensitive user credentials and message contents to unauthorized parties. Versions using alternative TLS backends remain unaffected. To secure your application, users are urged to upgrade to version 0.11.22 or later.

Affected Version(s)

lettre >= 0.10.1, < 0.11.22

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.