Skip to content

Mailpit

v1.30.4 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 18d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

email-testing go mailpit pop3-server smtp-relay smtp-server
+1 more
smtp-testing

Affected surfaces

rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 10d

Version v1.30.4 enforces command‑line length limits in SMTP and POP3 handlers and rejects oversized image dimensions before full decode.

Why it matters: Security fixes with severity 90 protect Mailpit from malformed input attacks; operators should upgrade immediately to mitigate risks.

Summary

AI summary

Updates Chore, Fix, and SMTP across a mixed release.

Changes in this release

Security Critical

Enforce command line length limits in SMTP and POP3 handlers

Enforce command line length limits in SMTP and POP3 handlers

Source: llm_adapter@2026-07-16

Confidence: high

Security Critical

Reject oversized image dimensions in thumbnail handler before full decode

Reject oversized image dimensions in thumbnail handler before full decode

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Exclude supported clients in HTML check results

Exclude supported clients in HTML check results

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

This release includes two important security fixes, so upgrading is strongly recommended.

Two security vulnerabilities affecting publicly exposed (SMTP) instances of Mailpit have been fixed in this release. Details are provided below.

Many thanks to the security researcher who responsibly disclosed these issues and helped improve Mailpit's security.

Security

Chore

  • Refactor browser storage settings for consistency (#715)
  • Update Go dependencies
  • Update node dependencies
  • Update caniemail test database
  • Update Github Action requirements

Fix

  • Exclude supported clients in HTML check results (#716)

Security Fixes

  • GHSA-w878-pj84-3j5v — Enforce command line length limits in SMTP and POP3 handlers
  • GHSA-75mr-qw9x-3r39 — Reject oversized image dimensions in thumbnail handler before full decode

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Mailpit

Get notified when new releases ship.

Sign up free

About Mailpit

Email testing tool and API for developers

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]