CVE-2026-23845 | axllent mailpit up to 1.28.2 HTML Check Feature html-check inlineRemoteCSS server-side request forgery (GHSA-6jxm-fv7w-rw5j / EUVD-2026-3296)
A vulnerability was found in axllent mailpit up to 1.28.2. It has been classified as critical. This affects the function inlineRemoteCSS of the file /api/v1/message/{ID}/html-check of the component HTML Check Feature. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-23845. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.