CVE-2026-23829 | axllent mailpit up to 1.28.2 Regular Expression RCPT TO/MAIL FROM crlf injection (GHSA-54wq-72mp-cq7c / CNNVD-202601-2973)
A vulnerability was found in axllent mailpit up to 1.28.2 and classified as problematic. Affected is an unknown function of the component Regular Expression Handler. Executing a manipulation of the argument RCPT TO/MAIL FROM can lead to crlf injection.
This vulnerability appears as CVE-2026-23829. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.