This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Summary
AI summaryUpdates Chore, SMTP, and https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Prevents SMTP DATA line exceeding MaxSize Prevents SMTP DATA line exceeding MaxSize Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Updates Go dependencies to latest versions Updates Go dependencies to latest versions Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Updates node dependencies to latest versions Updates node dependencies to latest versions Source: llm_adapter@2026-07-20 Confidence: medium |
— |
Full changelog
This release includes a security fix, so upgrading is strongly recommended.
One security vulnerability affecting publicly exposed (SMTP) instances of Mailpit has been fixed in this release. Details are provided below.
Many thanks to the security researcher who responsibly disclosed this issue and helped improve Mailpit's security.
Security
- Prevent SMTP DATA line exceeding MaxSize (GHSA-r553-m4fv-5v97)
Chore
- Update Go dependencies
- Update node dependencies
Security Fixes
- GHSA-r553-m4fv-5v97 — Prevent SMTP DATA line exceeding MaxSize
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]