Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4pj9-g833-qx53
  • crates.io/lettre
lettre has TLS hostname verification disabled when using Boring TLS backend 28 Jul
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-46428
  • github.com/lettre/lettre
lettre has TLS hostname verification disabled when using Boring TLS backend 20 Jul
  • Fix available
  • Severity - 9.1 (Critical)
RUSTSEC-2026-0141
  • crates.io/lettre
TLS hostname verification disabled when using Boring TLS backend 14 May
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-vc2p-r46x-m3vx
  • crates.io/lettre
Argument injection in lettre 25 Aug 2021
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2021-38189
  • github.com/lettre/lettre
See record for full details 08 Aug 2021
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-qc36-q22q-cjw3
  • crates.io/lettre
SMTP command injection in lettre 12 Jul 2021
  • Fix available
  • Severity - 9.8 (Critical)
RUSTSEC-2021-0069
  • crates.io/lettre
SMTP command injection in body 22 May 2021
  • Fix available
CVE-2020-28247
  • github.com/lettre/lettre
See record for full details 12 Nov 2020
  • No fix available
  • Severity - 5.3 (Medium)
RUSTSEC-2020-0069
  • crates.io/lettre
Argument injection in sendmail transport 11 Nov 2020
  • Fix available
  • Severity - 5.3 (Medium)