CVE-2026-84697
Last modified
CVE-2026-84697 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| axllent | mailpit | <= 1.31.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-84697?
How severe is CVE-2026-84697?
How do I fix CVE-2026-84697?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8468Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-84685The react-native-auth0 SDK's web platform implementation doe…6.5
- CVE-2026-8469Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-84694Coolify before 4.2.0 fails to properly escape environment va…8.8
- CVE-2026-84695BookStack before 26.05.4 contains a stored cross-site script…8.7
- CVE-2026-84696Phison PS3111-S11 controller firmware versions through SBFQT…8.2
- CVE-2026-84698PX4 Autopilot contains a heap buffer overflow vulnerability …6.5
- CVE-2026-84699Team Password Manager before 14.184.308 fails to enforce aut…9.1
- CVE-2026-8470IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3,…9.1
- CVE-2026-84700PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replicat…8.6
- CVE-2026-84701NocoBase fails to sanitize rich text field values in the rea…5.4
- CVE-2026-84702facefusion through 3.6.1 fails to normalize job identifiers …7.5
Are you affected by CVE-2026-84697?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
