Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g7hc-96xr-gvvx | MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery |
Thu, 12 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jstedfast:mimekit:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jstedfast
Jstedfast mimekit |
|
| Vendors & Products |
Jstedfast
Jstedfast mimekit |
Fri, 06 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \r\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1. | |
| Title | MimeKit: CRLF Injection in Quoted Local-Part Enables SMTP Command Injection and Email Forgery | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T20:54:29.184Z
Reserved: 2026-03-04T17:23:59.797Z
Link: CVE-2026-30227
Updated: 2026-03-09T20:47:36.375Z
Status : Analyzed
Published: 2026-03-06T21:16:16.607
Modified: 2026-03-12T15:34:59.480
Link: CVE-2026-30227
No data.
OpenCVE Enrichment
Updated: 2026-04-16T11:15:27Z
Github GHSA