<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:54:52.188483+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266115</id>
    <title>EUVD-2026-266115</title>
    <updated>2026-10-06T10:54:52.245786+00:00</updated>
    <content>EUVD-2026-266115</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23845</id>
    <title>fkie_cve-2026-23845</title>
    <updated>2026-10-06T10:54:52.245829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `&lt;link rel="stylesheet" href="..."&gt;` tags to inline them for testing. Version 1.28.3 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23845"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6jxm-fv7w-rw5j</id>
    <title>GHSA-6jxm-fv7w-rw5j — Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API</title>
    <updated>2026-10-06T10:54:52.245889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/axllent/mailpit</p>
<p>### Server-Side Request Forgery (SSRF) via HTML Check CSS Download</p>
<p>The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `&lt;link rel="stylesheet" href="..."&gt;` tags to inline them for testing.</p>
<p>#### Affected Components</p>
<p>- **Primary File:** `internal/htmlcheck/css.go` (lines 132-207)
- **API Endpoint:** `/api/v1/message/{ID}/html-check`
- **Handler:** `server/apiv1/other.go` (lines 38-75)
- **Vulnerable Functions:**
  - `inlineRemoteCSS()` - line 132
  - `downloadToBytes()` - line 193
  - `isURL()` - line 221</p>
<p>#### Technical Details</p>
<p>**1. Insufficient URL Validation (`isURL()` function):**</p>
<p>```go
// internal/htmlcheck/css.go:221-224
func isURL(str string) bool {
    u, err := url.Parse(str)
    return err == nil &amp;&amp; (u.Scheme == "http" || u.Scheme == "https") &amp;&amp; u.Host != ""
}
```</p>
<p>**2. Unrestricted Download (`downloadToBytes()` function):**</p>
<p>```go
// internal/htmlcheck/css.go:193-207
func downloadToBytes(url string) ([]byte, error) {
    client := http.Client{
        Timeout: 5 * time.Second,
    }</p>
<p>// Get the link response data
    resp, err := client.Get(url)  // ⚠️ VULNERABLE - No IP validation
    if err != nil {
        return nil, err
    }
    defer func() { _ = resp.Body.Close() }()</p>
<p>if resp.StatusCode != 200 {
        err := fmt.Errorf("error downloading %s", url)
        return nil, err
    }…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6jxm-fv7w-rw5j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0146</id>
    <title>WID-SEC-W-2026-0146 — MailPit: Mehrere Schwachstellen</title>
    <updated>2026-10-06T10:54:52.246104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MailPit ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0146"/>
  </entry>
</feed>
