Skip to content

Mailpit

v1.30.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

email-testing go mailpit pop3-server smtp-relay smtp-server
+1 more
smtp-testing

Summary

AI summary

Updates Chore, SMTP, and https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97 across a mixed release.

Changes in this release

Security Critical

Prevents SMTP DATA line exceeding MaxSize

Prevents SMTP DATA line exceeding MaxSize

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Updates Go dependencies to latest versions

Updates Go dependencies to latest versions

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Updates node dependencies to latest versions

Updates node dependencies to latest versions

Source: llm_adapter@2026-07-20

Confidence: medium

Full changelog

This release includes a security fix, so upgrading is strongly recommended.

One security vulnerability affecting publicly exposed (SMTP) instances of Mailpit has been fixed in this release. Details are provided below.

Many thanks to the security researcher who responsibly disclosed this issue and helped improve Mailpit's security.

Security

Chore

  • Update Go dependencies
  • Update node dependencies

Security Fixes

  • GHSA-r553-m4fv-5v97 — Prevent SMTP DATA line exceeding MaxSize

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Mailpit

Get notified when new releases ship.

Sign up free

About Mailpit

Email testing tool and API for developers

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]