lettre is vulnerable to Denial of Service (DoS)
55
Medium Risk
The blocking SMTP client accumulated peer response data in a string while reading line by line, without a hard ceiling on individual line length or total response size. A malicious or defective SMTP server could force unbounded growth and parsing work against the client. The reader now enforces caps inspired by common MTA limits and fails fast with an error when they are exceeded.
You are affected if you are using a version that falls within the vulnerable range.
lettre is vulnerable to Denial of Service (DoS) in versions 0.10.0 - 0.11.21.
Upgrade the lettre library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant