THREAT OPS › Threat News › [GHSA] GHSA-75mr-qw9x-3r39 (high) — Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
[GHSA] GHSA-75mr-qw9x-3r39 (high) — Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
GHSA-75mr-qw9x-3r39 Severity: high CVE: CVE-2026-67446
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
## Summary
Mailpit's thumbnail endpoint decodes attacker-supplied image attachments into a full raster before checking any decoded-pixel, dimension, or memory budget. A remote client that can store an email and reach the default web API can supply a compact high
MITRE ATT&CK techniques
- CompressionT1027.015
Indicators of compromise
- cd7661fd5b23cce1e218b583b21e157cfa612051sha1
- 6acf5b8f942ab0e007b1227d31dfb3c3303e8d13sha1
- b9f36312d750bdc59497a08fd9f4039925afd54esha1
- CVE-2026-67446cve
- sender@example.testemail
- victim@example.testemail
Original source: https://github.com/advisories/GHSA-75mr-qw9x-3r39