CyberRota Analysis
AI-GeneratedMailpit, an email testing tool, is vulnerable to a concurrency issue that can lead to a fatal error, causing the entire application to crash and disrupt its SMTP, POP3, and HTTP services. This vulnerability affects versions prior to 1.30.0, and organizations using Mailpit for development and testing should prioritize upgrading to the patched version to maintain service availability and prevent potential disruptions in their workflows.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the unsynchronized read coincides with a synchronized write, Go's runtime raises fatal error: concurrent map read and map write — a runtime.throw that is not recoverable by http.Server's handler-panic recover. The whole Mailpit process exits, taking the SMTP, POP3 and HTTP listeners down with it. Version 1.30.0 contains a patch.
Related CVEs
Other vulnerabilities affecting the same vendor(s)