SMTP Header Injection Vulnerability in SuperPlane by SuperPlaneHQ
CVE-2026-57511

6.3MEDIUM

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-57511?

SuperPlane versions prior to 0.30.0 are affected by an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers via CRLF sequences. This vulnerability occurs when attackers manipulate the unsanitized event payload title field sent through webhooks, potentially enabling them to add Bcc recipients for content exfiltration. Furthermore, attackers can forge the From address, bypassing security mechanisms like SPF and DKIM checks, or inject malicious Content-Type and MIME boundary headers, which could corrupt the message body and facilitate phishing attacks.

Affected Version(s)

superplane 0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
VulnCheck
.