
CVE-2026-27808: Return to Sender: Turning Mailpit into an Internal Port Scanner A critical Server-Side Request Forgery (SSRF) vulnerability in Mailpit's Link Check API allows unauthenticated remote attackers to map internal networks and enumerate clou... https://cvereports.com/reports/CVE-2026-27808
Post summary
A critical SSRF vulnerability in Mailpit's Link Check API allows unauthenticated remote attackers to map internal networks and enumerate cloud resources.

