Mailpit
- < 1.29.8
A denial-of-service vulnerability has been identified in Mailpit, an email testing tool for developers, in versions prior to 1.30.0. The issue arises in the screenshot/print proxy, which manages a cache of message assets. The proxy reads this cache without proper synchronization, allowing concurrent writes from a cleanup routine and CSS-rewriting process to cause a fatal runtime error. This unsynchronized access can be exploited by sending concurrent requests to the proxy, leading to a crash that terminates the Mailpit process and disrupts its SMTP, POP3, and HTTP services.
Exploitation of this vulnerability causes a fatal error that crashes the Mailpit process, terminating all active SMTP, POP3, and HTTP services.
To reproduce this vulnerability, send a message containing a stylesheet link to the Mailpit inbox via the SMTP or the API v1 send endpoint, both of which are unauthenticated by default. Then, issue concurrent requests to the proxy endpoint, targeting the same message's CSS URL with a crafted stylesheet that includes numerous URL entries to prolong the processing time. This can be automated with a script that manages the concurrent requests.
Users are advised to upgrade to Mailpit version 1.30.0 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.