CVE-2026-27808 | axllent mailpit up to 1.29.1 Link Check API link-check server-side request forgery (GHSA-mpf7-p9x7-96r3 / EUVD-2026-8775)
A vulnerability described as critical has been identified in axllent mailpit up to 1.29.1. Affected by this issue is some unknown functionality of the file /api/v1/message/{ID}/link-check of the component Link Check API. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-27808. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.