PT-2026-95067 · Cloudflare · Punchin-Email
CVE-2026-54649
·
Published
2026-09-17
·
Updated
2026-09-17
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
punchin-email versions prior to 1.5.0
Description
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. The
handleInbound() function delivers inbound alias mail using message.forward(), which silently removes the added Reply-To header meant to route responses through the relay. Consequently, when an operator replies to mail sent to an alias, the mail client may send the response directly from the private FORWARD TO inbox address, exposing that address to the correspondent. This disclosure is limited to the operator's own email address and does not allow for authentication bypass, code execution, or the exposure of third-party data.Recommendations
Update punchin-email to version 1.5.0.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Punchin-Email