Vulnerability in Mailpit Email Testing Tool by Axllent
CVE-2026-55187

5.8MEDIUM

Key Information:

Vendor

Axllent

Status
Vendor
CVE Published:
10 July 2026

What is CVE-2026-55187?

Mailpit, an email testing tool by Axllent, contains an improper input validation vulnerability due to an incomplete remediation from a prior issue. The affected versions, up to 1.30.2, utilize a deny-list that fails to block certain IPv6 transition mechanisms, allowing an attacker to potentially exploit the Link Check API. By delivering an email and invoking a specific API endpoint, an attacker could manipulate the safeDialContext to access internal destinations, using feedback from the API to identify internal services and cloud metadata endpoints. This vulnerability highlights the importance of robust input validation in software security.

Affected Version(s)

mailpit < 1.30.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.