VulnSea

axllent has 10 CVEs on record. Cadence is steady at roughly 5 per quarter. The busiest recent month was May 2026 with 4. The median CVSS is 5.8 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-770 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.8
Publish → KEV
Last 90 days
5 prev 5

Products

  • github.com/axllent/mailpit 10
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

axllent vulnerabilities

CVEs affecting axllent, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-67446Medium· 5.3⚖ disputed
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{i…

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.37%via NVD
CVE-2026-67445Medium· 5.3⚖ disputed
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses the verb or the RFC …

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.38%via NVD
CVE-2026-67447Medium· 5.3
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the completed SMT…

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.45%via NVD
CVE-2026-67448Medium· 6.5
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path,…

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.15%via NVD
CVE-2026-48824Medium· 5.3
2mo ago

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.42%via GHSA
CVE-2026-55187Medium· 5.8
3mo ago

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.38%via GHSA
CVE-2026-45712Medium· 5.9
4mo ago

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.25%via OSV
CVE-2026-45711Medium· 5.9
4mo ago

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.31%via OSV
CVE-2026-45709Medium· 5.8
4mo ago

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.27%via OSV
CVE-2026-45713High· 7.5
4mo ago

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Twilightaxllent · github.com/axllent/mailpitEPSS 0.39%via OSV
axllent vulnerabilities (CVEs) · VulnSea