You are here:
Home News Mailpit 1.30.6 Security Release!
Details
Last Updated: August 06, 2026
Security release!
Security
Prevent WebSocket CORS origin check bypass via percent-encoded path (GHSA-8r62-w5wh-fc5m )
Implement POP3 failed login tracking and disconnect after multiple attempts
Redact POP3 password in debug logs to prevent credential exposure
Chore
Add ReadHeaderTimeout to HTTP server configuration
Update node dependencies
Update Go dependencies
Update caniemail database
Update Github Actions dependencies
Fix
Prevent protocol desynchronization by draining oversized message data
Prevent marking already deleted POP messages for deletion
Ensure deleted POP3 messages are excluded from LIST and STAT commands
Update content type handling for attachments to ensure proper file downloads
Sanitise active Content-Type in attachment downloads
Escape file names in Content-Disposition header for thumbnail responses
Allow passwords with spaces in POP3 authentication
Implement dot-stuffing for TOP commands in POP3 server
Correct order of setting headers and writing HTTP error response
Handle client disconnection during DATA read with appropriate logging in SMTPD server (#721 )
Test
Add brute force POP3 login protection test
Add more WebSocket CORS tests
Enhance CORS middleware tests for HTML preview route handling
Sorry, this website uses features that your browser doesn't support. Upgrade to a newer version of Firefox , Chrome , Safari , or Edge and you'll be all set.
AI-powered knowledge base assistant. Press Ctrl+/ to open, Escape to close.
Hello! I'm your AI assistant. Ask me anything about our knowledge base and I'll help you find the information you need.