{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aaxllentmailpit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:axllent:mailpit:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-67445"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MailPit (\u003c 1.30.4)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Axllent"],"content_html":"\u003cp\u003eThe BSI has released an advisory regarding a Denial of Service (DoS) vulnerability affecting the MailPit application. MailPit, a popular email testing tool, contains a flaw that can be exploited by an unauthenticated, remote attacker to crash the service or render it unresponsive. This vulnerability poses a risk to development and testing environments where MailPit is deployed. Because the exploit can be initiated remotely without authentication, defenders should prioritize patching or restricting access to the MailPit interface to trusted networks to prevent service disruption. No specific CVE identifier was provided in the initial advisory at the time of publication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a Denial of Service, causing the MailPit application to become unavailable. This impacts development workflows that rely on MailPit for email testing, potentially halting testing cycles and affecting development productivity in impacted organizations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor the official MailPit release channels for updates or patches addressing this DoS vulnerability.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the MailPit web interface and SMTP service to authorized subnets only, preventing unauthenticated remote access.\u003c/li\u003e\n\u003cli\u003eReview network logs for unusual spikes in traffic directed at MailPit instances that may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:03:12Z","date_published":"2026-08-21T19:14:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mailpit-dos/","summary":"A vulnerability in the MailPit application allows a remote, unauthenticated attacker to trigger a Denial of Service condition, resulting in service unavailability.","title":"MailPit Denial of Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-mailpit-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:axllent:mailpit:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}