CVE-2026-23845: Axllent Mailpit
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `<link rel="stylesheet" href="...">` tags to inline them for testing. Version 1.28.3 fixes the issue.
Affected products
- Axllent Mailpit: before 1.28.3 (fixed in 1.28.3)
Published 2026-01-19. Last modified 2026-06-17.