Skip to content

Mailpit

v1.30.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

email-testing go mailpit pop3-server smtp-relay smtp-server
+1 more
smtp-testing

Affected surfaces

rce_ssrf

Summary

AI summary

Updates Chore, Feature, and Fix across a mixed release.

Full changelog

This release includes an important security fixes, so upgrading is strongly recommended.

This release includes a security fix which closes an additional IPv6 address bypasses that could allow the Link Check API to reach internal services or cloud metadata endpoints.

Security

  • Fix incomplete SSRF protection in IsInternalIP() detection for IPv6 transition mechanisms (GHSA-w4mc-hhc6-xp28)

Feature

  • Add wait support to readyz (#697)

Chore

  • Compress websocket messages once per broadcast to improve performance (#695)
  • Toggle websocket compression using HTTP compression setting (#695)
  • Update Github Actions dependencies
  • Update Go dependencies
  • Update node dependencies

Fix

  • Adjust header setting order in error response functions (#699)

Test

  • Add readyz tests

Security Fixes

  • GHSA-w4mc-hhc6-xp28 — Fix incomplete SSRF protection in IsInternalIP() detection for IPv6 transition mechanisms

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Mailpit

Get notified when new releases ship.

Sign up free

About Mailpit

Email testing tool and API for developers

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]