NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #343 by repository stars
Last release 5 days ago
03 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
366 releases · first in 2022
One column per quarter.
Prevent duplicate messages from being added in websocket handlers
Limit maximum MIME parts parsed per message to 500
This release includes a security fix, so upgrading is strongly recommended.
A vulnerability was fixed which allowed animated image attachments (APNG, GIF, WebP) to bypass the thumbnail pixel budget, potentially causing multi-gigabyte memory allocation when the thumbnail was rendered.
Many thanks to the security researcher who responsibly disclosed this issue and helped improve Mailpit's security.
Nothing published for this version
This release adds an optional feature to mitigate DNS rebinding attacks ( read more ), as well as other hardening fixes.
This release adds an optional feature to mitigate DNS rebinding attacks (read more), as well as other hardening fixes.
--allowed-hosts flag to mitigate DNS rebinding against the APINothing published for this version
Add debounced search refresh for filtered views on new messages
Add software license information
This release includes several security and bug fixes
Many thanks to the security researcher who responsibly disclosed a security issue, helping to improve Mailpit's security.
This release includes a security fix, so upgrading is strongly recommended.
One security vulnerability affecting publicly exposed (SMTP) instances of Mailpit has been fixed in this release. Details are provided below.
Many thanks to the security researcher who responsibly disclosed this issue and helped improve Mailpit's security.
This release includes two important security fixes, so upgrading is strongly recommended.
Two security vulnerabilities affecting publicly exposed (SMTP) instances of Mailpit have been fixed in this release. Details are provided below.
Many thanks to the security researcher who responsibly disclosed these issues and helped improve Mailpit's security.
Nothing published for this version
Add link check rate limiting and caching mechanism
This release includes an important security fixes, so upgrading is strongly recommended.
This release includes a security fix which closes an additional IPv6 address bypasses that could allow the Link Check API to reach internal services or cloud metadata endpoints.
Nothing published for this version
Extend request body size cap to all JSON API endpoints ( GHSA-28pq-6qxg-wg5r )
This release includes an important security fixes, so upgrading is strongly recommended.
This release introduces a default message size limit for both SMTP and api/v1/send to prevent DoS attacks via unbounded message sizes. This limit can be configured or disabled as needed, but the default is set to 50MB to provide a reasonable safeguard against abuse and align with some common email server limits.
A big thanks to the security researchers who reported these issues and helped improve Mailpit's security!
SMTP DATA and /api/v1/send body sizes (GHSA-fpxj-m5q8-fphw)mailpit dump --http <instance> via attacker-controlled message IDs (GHSA-qx5x-85p8-vg4j)--max-message-size flag and refactor message handling--max-message-size flag and refactor message handlingXCLIENT args before processingnpm ciThis is just a security release to update all Go, node and docker image dependencies.
This is just a security release to update all Go, node and docker image dependencies.
Bump docker/login-action from 3 to 4
Add sandbox attribute to message iframe for extra later of security (already protected via CSP headers)
Add filter functionality to message headers tab
Enhance CORS origin handling to respect host:port distinctions
Prevent Server-Side Request Forgery (SSRF) via Link Check API (GHSA-mpf7-p9x7-96r3)
Nothing published for this version
Nothing published for this version
Add CORS error logging and update error messages for failed CORS requests
Include message attachment checksums (MD5, SHA1 & SHA254) in API message summary
Increase allowed SMTP email address length to 1024 chars & return clearer SMTP responses for failures
Ensure SMTP TO & FROM addresses are RFC 5322 compliant and prevent header injection (GHSA-54wq-72mp-cq7c)
@ character in message tags & set max length to 100 characters per tag@ characterNothing published for this version
Nothing published for this version
Prevent Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to message data CVE-2026-22689
Nothing published for this version
Nothing published for this version
Restrict screenshot proxy to only support asset links contained in messages CVE-2026-21859
Nothing published for this version
Optionally propagate SMTP errors
Add type assertion for value in imaging assignment
Prevent potential information disclosure via indirect expvar library (Prometheus)
UI tweaks to pagination layout for clearer navigation
### Chore - Update Go dependencies - Update node dependencies - Update caniemail test database
Move HELO/EHLO hostname setting to the correct position in SMTP client creation
Add optional --no-release-check to version subcommand
Support optional UIDL argument in POP3 server
Allow rejected SMTP recipients to be silently dropped
Fix sendmail when using an --smtp-addr :
--smtp-addr <ip>:<port> (#542)Prevent integer overflow conversion to uint64
Allow unknown href link protocols in HTML view such as myapp://
Remove unused functionality/deadcode (golangci-lint)
Store username with messages, auto-tag, and UI display
Add relay config to preserve (keep) original Message-IDs when relaying messages
Add MP_DATA_FILE deprecation warning
Switch from unnecessary float64 to uint64 API values for App Information, message & attachment sizes
Add option to hide the "Delete all" button in web UI
Display unread count in app badge
Add ability to mark all search results as read
Add TLS relay support and refactor relay function
Use Message-ID header instead of Message-Id when generating new IDs (RFC 5322)
Message-ID header instead of Message-Id when generating new IDs (RFC 5322)Replace PrismJS with highlight.js for HTML syntax highlighting
Add configuration to set message compression level in db (0-3) (#447 & #448)
Your coding agent can read these notes before it upgrades. Set up the MCP server →