github.com/axllent/mailpit
Package main is the entrypoint
Security Advisories for github.com/axllent/mailpit in go
Moderate
about 2 months ago
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
go
github.com/axllent/mailpit
Moderate
about 2 months ago
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
go
github.com/axllent/mailpit
High
3 months ago
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
go
github.com/axllent/mailpit
Moderate
3 months ago
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
go
github.com/axllent/mailpit
Moderate
3 months ago
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
go
github.com/axllent/mailpit
Moderate
3 months ago
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
go
github.com/axllent/mailpit
Moderate
6 months ago
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API
go
github.com/axllent/mailpit
Moderate
7 months ago
Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API
go
github.com/axllent/mailpit
Moderate
7 months ago
Mailpit has an SMTP Header Injection via Regex Bypass
go
github.com/axllent/mailpit
Moderate
7 months ago
Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
go
github.com/axllent/mailpit
Moderate
7 months ago
Mailpit Proxy Endpoint has Server-Side Request Forgery (SSRF) vulnerability
go
github.com/axllent/mailpit