Mailpit 是面向开发人员的一款邮件测试工具及 API。在版本 1.29.0 至 1.30.6 之间,Mailpit 的 中用于验证来源中间件直接检查原始 是否以 开头,而 Go 的 路由机制则基于 URL 路径的百分号解码(percent-decoded)结果进行匹配;同时, 中配置了 直接返回 。因此,恶意网站可通过请求 (其中 是字母 的 URL 编码),绕过 函数,直接访问 的 WebSocket 处理程序。当用户访问该恶意网站后,攻击者可以从未认证且使用默认配置的 Mailpit 实例中获取实时消息
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67445 | 5.3 MEDIUM | Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection |
| CVE-2026-67446 | 5.3 MEDIUM | Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling |
| CVE-2026-67447 | 5.3 MEDIUM | Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement |
No comments yet