Mailpit SMTP DATA Line Memory Exhaustion (CVE Pending, Medium) -DC-Aug2026-1711

Listen to this Post

Mailpit enables SMTP by default and wires `config.MaxMessageSize` into srv.MaxSize. The DATA reader, however, enforces this cap only after reading a full line via bufio.Reader.ReadBytes('\n'). That means an unauthenticated SMTP client can send a single DATA line longer than the configured maximum (default 50 MiB) and force memory allocation before Mailpit returns the expected `552 5.3.4` rejection.

The vulnerable code path is in `internal/smtpd/smtpd.go`:

line, err := s.br.ReadBytes('\n')
if err != nil { return nil, err }
// ... dot-stuffing handling ...
if s.srv.MaxSize > 0 {
if len(data)+len(line) > s.srv.MaxSize {
_, _ = s.br.Discard(s.br.Buffered())
return nil, maxSizeExceeded(s.srv.MaxSize)
}
}

Because the size check occurs after `ReadBytes` has already buffered the complete line, an attacker can bypass the intended limit and cause memory exhaustion. With a 64 MiB single line, the process RSS jumps by ~130 MiB before the rejection is sent. This is a post-fix gap from the earlier unlimited SMTP DATA advisory (GHSA-fpxj-m5q8-fphw) – `srv.MaxSize` is now assigned and multi‑line accumulation is bounded, but individual lines are still unbounded.
Confirmed affected: v1.30.0, v1.30.3, v1.30.4 (published 2026‑07‑09), and the current develop branch as of 2026‑07‑09. No fixed version has been identified. The vulnerability is exploitable over the network if the SMTP listener is reachable by untrusted clients; deployments on internal/loopback networks have lower risk. The CVSS 3.1 score is 5.3 (Medium) with Low availability impact.

DailyCVE Form:

Platform: Mailpit
Version: v1.30.0 to develop
Vulnerability: SMTP DATA line memory
Severity: CVSS 5.3 Medium
date: 2026-07-09

Prediction: No patch yet

What Undercode Say:

Setup and run the proof of concept (Darwin ARM64 v1.30.3)
mkdir mailpit-v1.30.3-pov && cd mailpit-v1.30.3-pov
curl -fsSLO https://github.com/axllent/mailpit/releases/download/v1.30.3/mailpit-darwin-arm64.tar.gz
tar -xzf mailpit-darwin-arm64.tar.gz
chmod +x ./mailpit
./mailpit version
Save the PoC script as smtp_data_line_size_pov.py and execute
python3 ./smtp_data_line_size_pov.py

PoC script (snippet – the full script is provided in the original advisory):

!/usr/bin/env python3
import os, socket, subprocess, threading, time
...
def send_data_line(port, pid, label, payload_bytes, finish_message):
Connects, sends EHLO, MAIL, RCPT, DATA, then a single long line
without newline until after the entire payload is sent.
...
Creates a 64 MiB line and monitors RSS

The output on v1.30.3 shows:

oversized_single_data_line_bytes=67108864
oversized_response=552 5.3.4 Requested mail action aborted: exceeded storage allocation (52428800)
oversized_peak_delta_kib=132928

Exploit: (Educational Purposes!)

1. Reach the SMTP listener (default port 1025).

  1. Initiate an SMTP session with HELO, MAIL FROM, RCPT TO, and DATA.

3. Send the DATA header (e.g., `Subject: test\r\n\r\n`).

  1. Send a single line consisting of `payload_bytes` (e.g., 64 MiB) without a newline, then send `\r\n.\r\n` (or just `\r\n` to hang).
  2. Mailpit will allocate memory for the entire line before checking against MaxMessageSize, eventually returning `552 5.3.4` but after memory has grown.

6. Repeating concurrently can exhaust system memory.

Protection: from this CVE

  • Restrict SMTP listener to trusted networks or loopback only (e.g., --smtp 127.0.0.1:1025).
  • Use a network firewall or reverse proxy to limit incoming SMTP connections.
  • Monitor for excessive memory usage and restart the service if needed.
  • Apply a vendor patch as soon as one becomes available; until then, consider disabling SMTP if not required.

Impact:

A remote, unauthenticated attacker can cause Mailpit to allocate memory beyond the configured message size cap before the rejection is sent. By opening multiple concurrent connections and sending oversized single DATA lines, the attacker can create significant memory pressure, leading to service degradation or denial of service. The impact is bounded by network bandwidth and available host memory, but the configured `MaxMessageSize` does not prevent the allocation. The CVSS 3.1 score is 5.3 (Medium) with Low availability impact.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top