PatchSiren

lettre CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL lettre CVE published 2026-07-20

CVE-2026-46428

CVE-2026-46428 is a critical vulnerability in the lettre mailer library for Rust, caused by an inverted-boolean bug in lettre's `boring-tls` integration. This bug silently disables TLS hostname verification for callers using the default (strict) configuration, allowing an on-path attacker to intercept SMTP submission, including PLAIN/LOGIN credentials and message contents, against any lettre user built wi [truncated]