<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:47:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266115</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266115</link>
      <description>EUVD-2026-266115</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266115</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23845</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23845</link>
      <description>&lt;p&gt;Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `&amp;lt;link rel=&amp;#34;stylesheet&amp;#34; href=&amp;#34;...&amp;#34;&amp;gt;` tags to inline them for testing. Version 1.28.3 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `&amp;lt;link rel=&amp;#34;stylesheet&amp;#34; href=&amp;#34;...&amp;#34;&amp;gt;` tags to inline them for testing. Version 1.28.3 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23845</guid>
    </item>
    <item>
      <title>GHSA-6jxm-fv7w-rw5j — Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6jxm-fv7w-rw5j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/axllent/mailpit&lt;/p&gt;
&lt;p&gt;### Server-Side Request Forgery (SSRF) via HTML Check CSS Download&lt;/p&gt;
&lt;p&gt;The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `&amp;lt;link rel=&amp;#34;stylesheet&amp;#34; href=&amp;#34;...&amp;#34;&amp;gt;` tags to inline them for testing.&lt;/p&gt;
&lt;p&gt;#### Affected Components&lt;/p&gt;
&lt;p&gt;- **Primary File:** `internal/htmlcheck/css.go` (lines 132-207)
- **API Endpoint:** `/api/v1/message/{ID}/html-check`
- **Handler:** `server/apiv1/other.go` (lines 38-75)
- **Vulnerable Functions:**
  - `inlineRemoteCSS()` - line 132
  - `downloadToBytes()` - line 193
  - `isURL()` - line 221&lt;/p&gt;
&lt;p&gt;#### Technical Details&lt;/p&gt;
&lt;p&gt;**1. Insufficient URL Validation (`isURL()` function):**&lt;/p&gt;
&lt;p&gt;```go
// internal/htmlcheck/css.go:221-224
func isURL(str string) bool {
    u, err := url.Parse(str)
    return err == nil &amp;amp;&amp;amp; (u.Scheme == &amp;#34;http&amp;#34; || u.Scheme == &amp;#34;https&amp;#34;) &amp;amp;&amp;amp; u.Host != &amp;#34;&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;**2. Unrestricted Download (`downloadToBytes()` function):**&lt;/p&gt;
&lt;p&gt;```go
// internal/htmlcheck/css.go:193-207
func downloadToBytes(url string) ([]byte, error) {
    client := http.Client{
        Timeout: 5 * time.Second,
    }&lt;/p&gt;
&lt;p&gt;// Get the link response data
    resp, err := client.Get(url)  // ⚠️ VULNERABLE - No IP validation
    if err != nil {
        return nil, err
    }
    defer func() { _ = resp.Body.Close() }()&lt;/p&gt;
&lt;p&gt;if resp.StatusCode != 200 {
        err := fmt.Errorf(&amp;#34;error downloading %s&amp;#34;, url)
        return nil, err
    }…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/axllent/mailpit&lt;/p&gt;
&lt;p&gt;### Server-Side Request Forgery (SSRF) via HTML Check CSS Download&lt;/p&gt;
&lt;p&gt;The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `&amp;lt;link rel=&amp;#34;stylesheet&amp;#34; href=&amp;#34;...&amp;#34;&amp;gt;` tags to inline them for testing.&lt;/p&gt;
&lt;p&gt;#### Affected Components&lt;/p&gt;
&lt;p&gt;- **Primary File:** `internal/htmlcheck/css.go` (lines 132-207)
- **API Endpoint:** `/api/v1/message/{ID}/html-check`
- **Handler:** `server/apiv1/other.go` (lines 38-75)
- **Vulnerable Functions:**
  - `inlineRemoteCSS()` - line 132
  - `downloadToBytes()` - line 193
  - `isURL()` - line 221&lt;/p&gt;
&lt;p&gt;#### Technical Details&lt;/p&gt;
&lt;p&gt;**1. Insufficient URL Validation (`isURL()` function):**&lt;/p&gt;
&lt;p&gt;```go
// internal/htmlcheck/css.go:221-224
func isURL(str string) bool {
    u, err := url.Parse(str)
    return err == nil &amp;amp;&amp;amp; (u.Scheme == &amp;#34;http&amp;#34; || u.Scheme == &amp;#34;https&amp;#34;) &amp;amp;&amp;amp; u.Host != &amp;#34;&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;**2. Unrestricted Download (`downloadToBytes()` function):**&lt;/p&gt;
&lt;p&gt;```go
// internal/htmlcheck/css.go:193-207
func downloadToBytes(url string) ([]byte, error) {
    client := http.Client{
        Timeout: 5 * time.Second,
    }&lt;/p&gt;
&lt;p&gt;// Get the link response data
    resp, err := client.Get(url)  // ⚠️ VULNERABLE - No IP validation
    if err != nil {
        return nil, err
    }
    defer func() { _ = resp.Body.Close() }()&lt;/p&gt;
&lt;p&gt;if resp.StatusCode != 200 {
        err := fmt.Errorf(&amp;#34;error downloading %s&amp;#34;, url)
        return nil, err
    }…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6jxm-fv7w-rw5j</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0146 — MailPit: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0146</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MailPit ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MailPit ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0146</guid>
    </item>
  </channel>
</rss>
