SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-45712

MEDIUM · CVSS 5.9 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Mailpit, an email testing tool, is vulnerable to a concurrency issue that can lead to a fatal error, causing the entire application to crash and disrupt its SMTP, POP3, and HTTP services. This vulnerability affects versions prior to 1.30.0, and organizations using Mailpit for development and testing should prioritize upgrading to the patched version to maintain service availability and prevent potential disruptions in their workflows.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45712
Severity
MEDIUM
CVSS
5.9
EPSS
0.25%

Original NVD Description

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the unsynchronized read coincides with a synchronized write, Go's runtime raises fatal error: concurrent map read and map write — a runtime.throw that is not recoverable by http.Server's handler-panic recover. The whole Mailpit process exits, taking the SMTP, POP3 and HTTP listeners down with it. Version 1.30.0 contains a patch.

Related CVEs

Other vulnerabilities affecting the same vendor(s)