GHSA-54wq-72mp-cq7c · Severity: medium · Ecosystem: go — Mailpit has an SMTP Header Injection via Regex Bypass
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class. Version 1.28.3 fixes this issue.
Conclusion & alert: CVE-2026-23829 is rated High Exploit Risk (60.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.44%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.59% | 1.44% | -0.15% |
| 2 | 2026-05-22 | 0.94% | 1.59% | +0.66% |
| 3 | 2026-04-03 | — | 0.94% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
GHSA-54wq-72mp-cq7c · Severity: medium · Ecosystem: go — Mailpit has an SMTP Header Injection via Regex Bypass
| URL | Tags |
|---|---|
| https://github.com/axllent/mailpit/commit/36cc06c125954dec6673219dafa084e13cc14534 | Patch |
| https://github.com/axllent/mailpit/releases/tag/v1.28.3 | Product Release Notes |
| https://github.com/axllent/mailpit/security/advisories/GHSA-54wq-72mp-cq7c | Exploit Mitigation Third Party Advisory |