Memory and CPU Consumption Issue in Mailpit Email Testing Tool
CVE-2026-67446

5.3MEDIUM

Key Information:

Vendor

Axllent

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-67446?

Mailpit, an email testing tool for developers, has a vulnerability that allows attackers to exploit image attachments. In versions prior to 1.30.4, the application fails to appropriately validate the dimensions and memory use of attacker-supplied image attachments before processing them. This oversight can lead to excessive memory and CPU usage, especially when an unauthenticated client can craft and submit a malicious attachment. The issue arises in the Thumbnail handler endpoint, where images are decoded without initial checks, allowing large, compact images to overwhelm the system and degrade availability. The vulnerability has been addressed in version 1.30.4.

Affected Version(s)

mailpit < 1.30.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.