/Vulnerability Library

Mailpit < 1.28.2 - SMTP CRLF Injection

CVE-2026-23829
Verified

Description

Mailpit < 1.28 contains a header injection caused by insufficient regex validation of `RCPT TO` and `MAIL FROM` addresses in the SMTP server, letting attackers inject arbitrary SMTP headers, exploit requires crafted email addresses

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

mailpit

Published Date

January 21, 2026

Template Author

omarkurt

CVE-2026-23829.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE ID:
cve-2026-23829
CWE ID:
cwe-93

References

https://rosecurify.com/advisories/RO-26-002-mailpit-smtp-header-injection/https://github.com/axllent/mailpit/security/advisories/GHSA-54wq-72mp-cq7c

Remediation Steps

Upgrade Mailpit to version 1.28.3 or later which updates the regex to explicitly exclude all ASCII control characters (\x00-\x1f) from email addresses.