Remote Command Injection in Mailpit Affects Email Testing Tool by Axllent
CVE-2026-67445
5.3MEDIUM
What is CVE-2026-67445?
Mailpit, an email testing tool and API for developers, contains a vulnerability that allows unauthenticated remote SMTP clients to exploit oversized command lines. This occurs because Mailpit inadvertently processes commands exceeding the RFC 5321 limit without enforcing critical size constraints. The issue can lead to memory exhaustion, resulting in degraded performance and availability of the service. The vulnerability has been addressed in version 1.30.4, highlighting the importance of updating to mitigate associated risks.
Affected Version(s)
mailpit < 1.30.4
