CVE-2026-84697

Source
https://cve.org/CVERecord?id=CVE-2026-84697
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84697.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84697
Published
2026-09-02T00:37:53.020Z
Modified
2026-09-03T03:48:19.972222378Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix
Details

Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84697.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/axllent/mailpit

Affected ranges

Type
GIT
Repo
https://github.com/axllent/mailpit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.31.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84697.json"