CVE-2026-67445
Summary
Mailpit's SMTP server reads each command line with an unbounded bufio.Reader.ReadString('\n') before parsing the command or enforcing any protocol length limit. A remote SMTP client can send an oversized single command line and force Mailpit to allocate attacker-controlled memory before the server returns a syntax error or times out, even though RFC 5321 limits SMTP command lines to 512 octets including CRLF.
Technical Details
Mailpit enables SMTP by default. config/config.go sets SMTPListen = "[::]:1025", and cmd/root.go calls smtpd.Listen() during normal startup. The SMTP server configures recipient and message DATA size limits in internal/smtpd/main.go, including the default 50 MiB MaxMessageSize, but those limits do not apply to command lines.
The vulnerable path is in the SMTP command loop. internal/smtpd/smtpd.go calls s.readLine() for every command before parsing the verb or arguments:
line, err := s.readLine()
if err != nil {
if netErr, ok := err.(net.Error); ok && netErr.Timeout() {
s.writef("421 4.4.2 %s %s ESMTP Service closing transmission channel after timeout exceeded", s.srv.Hostname, s.srv.AppName)
}
break
}
verb, args := s.parseLine(line)
readLine() then buffers until newline without a maximum length:
func (s *session) readLine() (string, error) {
if s.srv.Timeout > 0 {
_ = s.conn.SetReadDeadline(time.Now().Add(s.srv.Timeout))
}
line, err := s.br.ReadString('\n')
if err != nil {
return "", err
}
line = strings.TrimSpace(line)
return line, err
}
This violates the SMTP command-line invariant before later validation can help. Address length validation in extractAndValidateAddress() runs only after the entire command line has already been buffered and parsed. The DATA reader has a separate srv.MaxSize check, but the issue is pre-DATA command input.
PoV
The following bounded test exercises the same command reader with a normal NOOP control and an 8 MiB oversized command line:
package smtpd
import (
"bufio"
"bytes"
"strings"
"testing
⚡ Watch CVE-2026-67445
Get an email if CVE-2026-67445 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-67445)