๐Ÿ” CVE Alert

CVE-2026-46428

UNKNOWN 0.0

lettre has TLS hostname verification disabled when using Boring TLS backend

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configuration. An on-path attacker presenting any chain-valid certificate for any domain can intercept SMTP submission, including PLAIN/LOGIN credentials and message contents, against any lettre user built with the `boring-tls` feature. Other TLS backends (`native-tls`, `rustls`) are unaffected. Version 0.11.22 patches the issue.

CWE CWE-295
Vendor lettre
Product lettre
Published Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for lettre lettre

Be the first to know when new unknown vulnerabilities affecting lettre lettre are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

lettre / lettre
>= 0.10.1, < 0.11.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lettre/lettre/security/advisories/GHSA-4pj9-g833-qx53 github.com: https://github.com/lettre/lettre/commit/f5efffc88360dbdbfcef80f465e42d5bce68ca35 github.com: https://github.com/lettre/lettre/releases/tag/v0.11.22 rustsec.org: https://rustsec.org/advisories/RUSTSEC-2026-0141.html