CVE Explorer
CVE-2026-23829
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when use
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-93","description":"CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-150","description":"CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"mailpit","vendor":"axllent","versions":[{"status":"affected","version":"< 1.28.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-93","description":"CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-150","description":"CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://github.com/axllent/mailpit/commit/36cc06c125954dec6673219dafa084e13cc14534","tags":["x_refsource_MISC"],"url":"https://github.com/axllent/mailpit/commit/36cc06c125954dec6673219dafa084e13cc14534"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/references/1
{"name":"https://github.com/axllent/mailpit/releases/tag/v1.28.3","tags":["x_refsource_MISC"],"url":"https://github.com/axllent/mailpit/releases/tag/v1.28.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/references/2
{"name":"https://github.com/axllent/mailpit/security/advisories/GHSA-54wq-72mp-cq7c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/axllent/mailpit/security/advisories/GHSA-54wq-72mp-cq7c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80eaca68ed1ad97f159d70734b98dd085ea236e61cd5215408120d23ef92edaa · sha256:b1bddfb90164e944… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.