CVE Feed

    Dashboard / CVE / CVE-2026-84697

    CVE-2026-84697

    Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.

    Published:Sep 2, 2026
    Last Modified:Sep 2, 2026
    EPS:Sep 2, 2026
    EPSS Score:0.00245
    CVSS Score:5.3

    Affected Products

    Vendor
    Axllent
    Product
    Mailpit

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High