PT-2026-95067 · Cloudflare · Punchin-Email

CVE-2026-54649

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions punchin-email versions prior to 1.5.0
Description punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. The handleInbound() function delivers inbound alias mail using message.forward(), which silently removes the added Reply-To header meant to route responses through the relay. Consequently, when an operator replies to mail sent to an alias, the mail client may send the response directly from the private FORWARD TO inbox address, exposing that address to the correspondent. This disclosure is limited to the operator's own email address and does not allow for authentication bypass, code execution, or the exposure of third-party data.
Recommendations Update punchin-email to version 1.5.0.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54649
GHSA-2PH7-69XM-HMWV

Affected Products

Punchin-Email