What is CVE-2026-57511?
SuperPlane versions before 0.30.0 contain an SMTP header injection vulnerability where unauthenticated attackers can inject arbitrary SMTP headers via CRLF sequences in the event payload title field delivered through webhooks. This allows manipulation of email headers. Affected systems should be updated to version 0.30.0 or later immediately.
Azərbaycanca: SuperPlane-in 0.30.0-dən əvvəlki versiyalarında, vebhook vasitəsilə göndərilən hadisə başlığı sahəsindəki CRLF ardıcıllıqları vasitəsilə autentifikasiya olunmamış SMTP başlıq inyeksiyası zəifliyi mövcuddur. Bu, zərərli şəxslərə e-poçt başlıqlarını manipulyasiya etməyə imkan verir. Təsirlənmiş sistemlərin dərhal 0.30.0 və ya daha yuxarı versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of SuperPlane are vulnerable to the SMTP header injection?
All SuperPlane versions before 0.30.0 are affected by this vulnerability. Version 0.30.0 and later fix this security flaw.
How can an attacker manipulate email headers through this vulnerability?
Attackers can inject arbitrary SMTP headers by inserting CRLF sequences into the event payload title field delivered through webhooks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.