Skip to content

Known CVE

Mailpit < 1.28.2 - SMTP CRLF Injection

Mailpit < 1.28 contains a header injection caused by insufficient regex validation of `RCPT TO` and `MAIL FROM` addresses in the SMTP server, letting attackers inject arbitrary SMTP headers, exploit requires crafted email addresses

CVE-2026-23829

Medium2026CVSS 5.3CWE-93

cve2026 · tcp · crlf · smtp · mailpit

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website