CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67445

highCVSS 7.5covered by 2 sourcesfirst seen 2026-08-20
Summary Mailpit's SMTP server reads each command line with an unbounded bufio.Reader.ReadString('\n') before parsing the command or enforcing any protocol length limit. A remote SMTP client can send an oversized single command line and force Mailpit to allocate attacker-controlled memory before the server returns a syntax error or times out, even though RFC 5321 limits SMTP command lines to 512 octets including CRLF. Technical Details Mailpit enables SMTP by default. config/config.go sets SMTPListen = "[::]:1025", and cmd/root.go calls smtpd.Listen() during normal startup. The SMTP server configures recipient and message DATA size limits in internal/smtpd/main.go, including the default 50 MiB MaxMessageSize, but those limits do not apply to command lines. The vulnerable path is in the SMTP command loop. internal/smtpd/smtpd.go calls s.readLine() for every command before parsing the verb or arguments: line, err := s.readLine() if err != nil { if netErr, ok := err.(net.Error); ok && netErr.Timeout() { s.writef("421 4.4.2 %s %s ESMTP Service closing transmission channel after timeout exceeded", s.srv.Hostname, s.srv.AppName) } break } verb, args := s.parseLine(line) readLine() then buffers until newline without a maximum length: func (s *session) readLine() (string, error) { if s.srv.Timeout > 0 { _ = s.conn.SetReadDeadline(time.Now().Add(s.srv.Timeout)) } line, err := s.br.ReadString('\n') if err != nil { return "", err } line = strings.TrimSpace(line) return line, err } This violates the SMTP command-line invariant before later validation can help. Address length validation in extractAndValidateAddress() runs only after the entire command line has already been buffered and parsed. The DATA reader has a separate srv.MaxSize check, but the issue is pre-DATA command input. PoV The following bounded test exercises the same command reader with a normal NOOP control and an 8 MiB oversized command line: package smtpd import ( "bufio" "bytes" "strings" "testing

⚡ Watch CVE-2026-67445

Get an email if CVE-2026-67445 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-67445

CVE.org record

Embed the live status

CVE-2026-67445 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67445 status](https://www.csirts.com/badge/CVE-2026-67445)](https://www.csirts.com/cve/CVE-2026-67445)