github axllent/mailpit v1.31.2

6 hours ago

This release includes a security fix, so upgrading is strongly recommended.

A vulnerability was fixed which allowed animated image attachments (APNG, GIF, WebP) to bypass the thumbnail pixel budget, potentially causing multi-gigabyte memory allocation when the thumbnail was rendered.

Many thanks to the security researcher who responsibly disclosed this issue and helped improve Mailpit's security.

Security

Feature

  • Add major version tag for Docker images in workflow (#734)

Chore

  • Improve message rendering performance with envelope caching
  • Update Go dependencies
  • Update node dependencies
  • Update caniemail test database

Fix

  • Re-quote local-parts in API JSON responses (#732)

Don't miss a new mailpit release

NewReleases is sending notifications on new releases.