Remote Command Injection in Mailpit Affects Email Testing Tool by Axllent
CVE-2026-67445

5.3MEDIUM

Key Information:

Vendor

Axllent

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-67445?

Mailpit, an email testing tool and API for developers, contains a vulnerability that allows unauthenticated remote SMTP clients to exploit oversized command lines. This occurs because Mailpit inadvertently processes commands exceeding the RFC 5321 limit without enforcing critical size constraints. The issue can lead to memory exhaustion, resulting in degraded performance and availability of the service. The vulnerability has been addressed in version 1.30.4, highlighting the importance of updating to mitigate associated risks.

Affected Version(s)

mailpit < 1.30.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.