A AegiFlow
CRITICALCVSS 9.1EPSS 0.2%

CVE-2026-46428

CVE-2026-46428 updated by NVD

Published
2026-07-28
Modified
2026-07-28
EPSS percentile
9%
Sources
github-advisory, nvd

Summary

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configuration. An on-path attacker presenting any chain-valid certificate for any domain can intercept SMTP submission, including PLAIN/LOGIN credentials and message contents, against any lettre user built with the `boring-tls` feature. Other TLS backends (`native-tls`, `rustls`) are unaffected. Version 0.11.22 patches the issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
rustlettre0.11.22

Remediation: Upgrade to 0.11.22 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.