We found results for “”
CVE-2026-23845
Good to know:
Date: January 19, 2026
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature ("/api/v1/message/{ID}/html-check") is designed to analyze HTML emails for compatibility. During this process, the "inlineRemoteCSS()" function automatically downloads CSS files from external "<link rel="stylesheet" href="...">" tags to inline them for testing. Version 1.28.3 fixes the issue.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Server-Side Request Forgery (SSRF)
CWE-918Top Fix
Upgrade Version
Upgrade to version github.com/axllent/mailpit - v1.28.3;github.com/axllent/mailpit - v1.28.3
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


