Логотип exploitDog
bind:CVE-2026-23845
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23845

Количество 2

Количество 2

nvd логотип

CVE-2026-23845

21 день назад

Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `<link rel="stylesheet" href="...">` tags to inline them for testing. Version 1.28.3 fixes the issue.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-6jxm-fv7w-rw5j

20 дней назад

Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23845

Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `<link rel="stylesheet" href="...">` tags to inline them for testing. Version 1.28.3 fixes the issue.

CVSS3: 5.8
0%
Низкий
21 день назад
github логотип
GHSA-6jxm-fv7w-rw5j

Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API

CVSS3: 5.8
0%
Низкий
20 дней назад

Уязвимостей на страницу