<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:34:02.217714+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266130</id>
    <title>EUVD-2026-266130</title>
    <updated>2026-10-06T13:34:02.220871+00:00</updated>
    <content>EUVD-2026-266130</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23829</id>
    <title>fkie_cve-2026-23829</title>
    <updated>2026-10-06T13:34:02.220909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class. Version 1.28.3 fixes this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-54wq-72mp-cq7c</id>
    <title>GHSA-54wq-72mp-cq7c — Mailpit has an SMTP Header Injection via Regex Bypass</title>
    <updated>2026-10-06T13:34:02.220945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/axllent/mailpit</p>
<p># Vulnerability Report: SMTP Header Injection via Regex Bypass</p>
<p>**Vulnerable Code:** `mailpit/internal/smtpd/smtpd.go`</p>
<p>## Executive Summary
Mailpit's SMTP server is vulnerable to **Header Injection** due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including carriage return characters (`\r`) in the email address. This header injection occurs because the regex intended to filter control characters fails to exclude `\r` and `\n` when used inside a character class.</p>
<p>## RFC Compliance &amp; Design Analysis
**"Is this behavior intentional for a testing tool?"**
No. While testing tools are often permissive, this specific behavior violates the core SMTP protocol and fails the developer's own intent.</p>
<p>1.  **RFC 5321 Violation:** The SMTP protocol strictly forbids Control Characters (CR, LF, Null) in the envelope address (`Mailbox`).
    *   *RFC 5321 Section 4.1.2:* A `Mailbox` consists of an `Atom` or `Quoted-string`. An `Atom` explicitly excludes "specials, SPACE and CTLs" (Control Characters).
2.  **Failed Intent:** The existence of `\v` in the regex `[^&lt;&gt;\v]` proves the developer **intended** to block vertical whitespace. The vulnerability is that `\v` in Go regex (`re2`) inside brackets `[]` matches *only* Vertical Tab, not CR/LF. If the design were to allow everything, the `\v` exclusion wouldn't exist.
3.  **Data Corruption:** Allowing `\r` results in the ge…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-54wq-72mp-cq7c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0146</id>
    <title>WID-SEC-W-2026-0146 — MailPit: Mehrere Schwachstellen</title>
    <updated>2026-10-06T13:34:02.221012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MailPit ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0146"/>
  </entry>
</feed>
