← Back

Lettre

lettre

Vendor: Lettre • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lettre
1Lettre
Jun 17, 2026
Aug 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.
1Lettre
1Lettre
Jun 17, 2026
Nov 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.