FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mailpit -- Multi-frame animation bypass of thumbnail pixel budget

Affected packages
mailpit < 1.31.2

Details

VuXML ID c1980e14-b424-11f1-bd9f-10ffe07f9334
Discovery 2026-09-19
Entry 2026-09-19

Mailpit author reports:

The fix for CVE-2026-67446 / GHSA-75mr-qw9x-3r39 ("Thumbnail generation decodes unbounded image dimensions before scaling", patched in v1.30.4) bounds only the width × height of a single frame. The decoded-size budget is still not enforced over frame count, so an animated PNG whose per-frame dimensions sit just under the limit still expands to a multiple of it. A remote, unauthenticated client can deliver such an attachment over SMTP and then request one thumbnail to force a multi-gigabyte native allocation.

References

URL https://github.com/axllent/mailpit/security/advisories/GHSA-2vgv-6hcp-mf43