CVE-2026-67447 PUBLISHED

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

Assigner: GitHub_M
Reserved: 29.07.2026 Published: 20.08.2026 Updated: 20.08.2026

Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the completed SMTP DATA line against Server.MaxSize. An unauthenticated SMTP client can send a single line larger than the configured MaxMessageSize, causing the full line to be allocated before Mailpit returns the 552 5.3.4 rejection. This post-fix gap remains after normal multi-line DATA accumulation was bounded, and concurrent oversized lines can create substantial memory pressure beyond the configured message-size cap. This issue is fixed in version 1.30.5.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor axllent
Product mailpit
Versions
  • Version >= 1.30.0, < 1.30.5 is affected

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling CWE