mailcatcher

Install command:
brew install mailcatcher

Catches mail and serves it through a dream

https://mailcatcher.me

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/mailcatcher.json

Formula code: mailcatcher.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
tahoe
sequoia
sonoma
macOS on
Intel
sonoma
Linux ARM64
x86_64

Current versions:

stable 0.10.0

Revision: 2

Depends on:

libyaml 0.2.5 YAML Parser
openssl@3 3.6.3 Cryptography and SSL/TLS Toolkit
ruby 4.0.6 Powerful, clean, object-oriented scripting language

Depends on when building from source:

pkgconf 3.0.5 Package compiler and linker metadata toolkit

Known vulnerabilities in the current version:

GHSA-hxx2-7vcw-mqr3 (medium) Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
GHSA-7g2v-jj9q-g3rg (medium) Possible Log Injection in Rack::CommonLogger
GHSA-7fc5-f82f-cx69 (medium) Possible DoS by memory exhaustion in net-imap
GHSA-8cgq-6mh2-7j6v Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
GHSA-7wqh-767x-r66v (high) Local File Inclusion in Rack::Static
GHSA-vpfw-47h7-xj4g (medium) Rack session gets restored after deletion
GHSA-j3g3-5qv5-52mj net-imap rubygem vulnerable to possible DoS by memory exhaustion
GHSA-gjh7-p2fx-99vx (high) Rack has an Unbounded-Parameter DoS in Rack::QueryParser
GHSA-625h-95r8-8xpm (high) Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separate...
GHSA-p543-xpfm-54cp (high) Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
GHSA-w9pc-fmgc-vxvw (high) Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exh...
GHSA-wpv5-97wm-hp9c (high) Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
GHSA-r657-rxjc-j557 (medium) Rack has a Possible Information Disclosure Vulnerability
GHSA-6xw4-3v39-52mm (high) Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
GHSA-mr3q-g2mv-mr4q Sinatra is vulnerable to ReDoS through ETag header value generation
GHSA-mxw3-3hh2-x2mh (high) Rack has a Directory Traversal via Rack:Directory
GHSA-whrj-4476-wvmp (medium) Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
GHSA-vgpv-f759-9wx3 (medium) Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
GHSA-v569-hp3g-36wr (high) Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding he...
GHSA-7mqq-6cf9-v2qp (medium) Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
GHSA-h2jq-g4cq-5ppq (high) Rack::Static prefix matching can expose unintended files under the static root
GHSA-q4qf-9j86-f5mh (medium) Rack:: Static header_rules bypass via URL-encoded paths
GHSA-x8cg-fq8g-mxfx (medium) Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
GHSA-8vqr-qjwx-82mw (high) Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
GHSA-qv7j-4883-hwh7 (medium) Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
GHSA-q2ww-5357-x388 (medium) Rack has Content-Length mismatch in Rack::Files error responses
GHSA-q2mw-fvj9-vvcw net-imap has quadratic complexity when reading response literals
GHSA-vcgp-9326-pqcp net-imap vulnerable to STARTTLS stripping via invalid response timing
GHSA-87pf-fpwv-p7m7 net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
GHSA-hm49-wcqc-g2xg net-imap vulnerable to command Injection via "raw" arguments to multiple commands
GHSA-75xq-5h9v-w6px (medium) net-imap vulnerable to command Injection via unvalidated Symbol inputs
GHSA-8p34-64r3-mwg8 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
GHSA-c4fp-cxrr-mj66 Net::IMAP: Denial of Service via incomplete raw argument validation
GHSA-46q3-7gv7-qmgg Net::IMAP: Command Injection via ID command argument
GHSA-ghhp-3qvg-889p websocket-driver: Memory exhaustion via abuse of protocol length headers
GHSA-33ph-fccm-39pj websocket-driver: Resource limit bypass via message compression
GHSA-8j3g-f24p-4mpw websocket-driver: Memory exhaustion in HTTP header parser
GHSA-28hh-pr2h-2w89 sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
GHSA-2x63-gw47-w4mm websocket-driver-ruby: Denial of service via malformed Host header

Data from Homebrew/advisory-database. Run brew vulns mailcatcher for a live check.

Analytics:

30 days90 days365 days
Installs2777515
Installs on Request2777515
Build Errors0