CVE-2026-23829
CVE-2026-23829 is a medium-severity vulnerability in Axllent Mailpit with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-93.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 1% (72nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-3297
- Weakness: CWE-93
- Affected product: Axllent Mailpit
- Published:
- Last modified:
Description
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class. Version 1.28.3 fixes this issue.
Frequently asked questions
- What is CVE-2026-23829?
- Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class. Version 1.28.3 fixes this issue.
- How severe is CVE-2026-23829?
- CVE-2026-23829 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-23829 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (72nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-23829?
- CVE-2026-23829 affects Axllent Mailpit. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-23829?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-23829 have an EU (EUVD) identifier?
- Yes. CVE-2026-23829 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-3297.
- When was CVE-2026-23829 published?
- CVE-2026-23829 was published on 2026-01-19 and last updated on 2026-06-17.
References
- https://github.com/axllent/mailpit/commit/36cc06c125954dec6673219dafa084e13cc14534
- https://github.com/axllent/mailpit/releases/tag/v1.28.3
- https://github.com/axllent/mailpit/security/advisories/GHSA-54wq-72mp-cq7c
Affected products (1)
- cpe:2.3:a:axllent:mailpit:*:*:*:*:*:*:*:*
More vulnerabilities in Axllent Mailpit
- CVE-2026-45713 — High (CVSS 7.5): Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a…
- CVE-2026-22689 — Medium (CVSS 6.5): Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is…
- CVE-2026-45712 — Medium (CVSS 5.9): Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy…
- CVE-2026-45711 — Medium (CVSS 5.9): Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url>…
- CVE-2026-45709 — Medium (CVSS 5.8): Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side…
- CVE-2026-27808 — Medium (CVSS 5.8): Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API…
All CVEs affecting Axllent Mailpit →
Other CWE-93 (CRLF Injection) vulnerabilities
- CVE-2026-77550 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability…
- CVE-2024-51501 — Critical (CVSS 10.0): Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit…
- CVE-2026-100717 — Critical (CVSS 9.9): froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return…
- CVE-2026-90937 — Critical (CVSS 9.9): froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated…
- CVE-2026-70615 — Critical (CVSS 9.9): boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users…
- CVE-2026-45372 — Critical (CVSS 9.9): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's…