This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v1.30.4 enforces command‑line length limits in SMTP and POP3 handlers and rejects oversized image dimensions before full decode.
Why it matters: Security fixes with severity 90 protect Mailpit from malformed input attacks; operators should upgrade immediately to mitigate risks.
Summary
AI summaryUpdates Chore, Fix, and SMTP across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Enforce command line length limits in SMTP and POP3 handlers Enforce command line length limits in SMTP and POP3 handlers Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | Critical |
Reject oversized image dimensions in thumbnail handler before full decode Reject oversized image dimensions in thumbnail handler before full decode Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Exclude supported clients in HTML check results Exclude supported clients in HTML check results Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
This release includes two important security fixes, so upgrading is strongly recommended.
Two security vulnerabilities affecting publicly exposed (SMTP) instances of Mailpit have been fixed in this release. Details are provided below.
Many thanks to the security researcher who responsibly disclosed these issues and helped improve Mailpit's security.
Security
- Enforce command line length limits in SMTP and POP3 handlers (GHSA-w878-pj84-3j5v)
- Reject oversized image dimensions in thumbnail handler before full decode (GHSA-75mr-qw9x-3r39)
Chore
- Refactor browser storage settings for consistency (#715)
- Update Go dependencies
- Update node dependencies
- Update caniemail test database
- Update Github Action requirements
Fix
- Exclude supported clients in HTML check results (#716)
Security Fixes
- GHSA-w878-pj84-3j5v — Enforce command line length limits in SMTP and POP3 handlers
- GHSA-75mr-qw9x-3r39 — Reject oversized image dimensions in thumbnail handler before full decode
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]