Ralph Slooten
4 exploits
Active since Jan 2026
Mailpit < 1.28.3 - SMTP Header Injection via RCPT TO and MAIL FROM Address Validation
CVSS 5.3
Mailpit < 1.29.2 - Unauthenticated Server-Side Request Forgery via Link Check API
CVSS 5.8
Mailpit < 1.28.1 - Server-Side Request Forgery via Proxy Endpoint
CVSS 5.8
Mailpit < 1.28.2 - Cross-Site WebSocket Hijacking via Missing Origin Validation
CVSS 6.5