mailcatcher
Install command:
brew install mailcatcherCatches mail and serves it through a dream
License: MIT
Development: Pull requests
Formula JSON API: /api/formula/mailcatcher.json
Formula code: mailcatcher.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 0.10.0 |
Revision: 2
Depends on:
| libyaml | 0.2.5 | YAML Parser |
| openssl@3 | 3.6.3 | Cryptography and SSL/TLS Toolkit |
| ruby | 4.0.6 | Powerful, clean, object-oriented scripting language |
Depends on when building from source:
| pkgconf | 3.0.5 | Package compiler and linker metadata toolkit |
Known vulnerabilities in the current version:
| GHSA-hxx2-7vcw-mqr3 (medium) | Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision |
| GHSA-7g2v-jj9q-g3rg (medium) | Possible Log Injection in Rack::CommonLogger |
| GHSA-7fc5-f82f-cx69 (medium) | Possible DoS by memory exhaustion in net-imap |
| GHSA-8cgq-6mh2-7j6v | Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection |
| GHSA-7wqh-767x-r66v (high) | Local File Inclusion in Rack::Static |
| GHSA-vpfw-47h7-xj4g (medium) | Rack session gets restored after deletion |
| GHSA-j3g3-5qv5-52mj | net-imap rubygem vulnerable to possible DoS by memory exhaustion |
| GHSA-gjh7-p2fx-99vx (high) | Rack has an Unbounded-Parameter DoS in Rack::QueryParser |
| GHSA-625h-95r8-8xpm (high) | Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separate... |
| GHSA-p543-xpfm-54cp (high) | Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) |
| GHSA-w9pc-fmgc-vxvw (high) | Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exh... |
| GHSA-wpv5-97wm-hp9c (high) | Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion) |
| GHSA-r657-rxjc-j557 (medium) | Rack has a Possible Information Disclosure Vulnerability |
| GHSA-6xw4-3v39-52mm (high) | Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing |
| GHSA-mr3q-g2mv-mr4q | Sinatra is vulnerable to ReDoS through ETag header value generation |
| GHSA-mxw3-3hh2-x2mh (high) | Rack has a Directory Traversal via Rack:Directory |
| GHSA-whrj-4476-wvmp (medium) | Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href |
| GHSA-vgpv-f759-9wx3 (medium) | Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass. |
| GHSA-v569-hp3g-36wr (high) | Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding he... |
| GHSA-7mqq-6cf9-v2qp (medium) | Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory |
| GHSA-h2jq-g4cq-5ppq (high) | Rack::Static prefix matching can expose unintended files under the static root |
| GHSA-q4qf-9j86-f5mh (medium) | Rack:: Static header_rules bypass via URL-encoded paths |
| GHSA-x8cg-fq8g-mxfx (medium) | Rack's multipart byte range processing allows denial of service via excessive overlapping ranges |
| GHSA-8vqr-qjwx-82mw (high) | Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads |
| GHSA-qv7j-4883-hwh7 (medium) | Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect |
| GHSA-q2ww-5357-x388 (medium) | Rack has Content-Length mismatch in Rack::Files error responses |
| GHSA-q2mw-fvj9-vvcw | net-imap has quadratic complexity when reading response literals |
| GHSA-vcgp-9326-pqcp | net-imap vulnerable to STARTTLS stripping via invalid response timing |
| GHSA-87pf-fpwv-p7m7 | net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication |
| GHSA-hm49-wcqc-g2xg | net-imap vulnerable to command Injection via "raw" arguments to multiple commands |
| GHSA-75xq-5h9v-w6px (medium) | net-imap vulnerable to command Injection via unvalidated Symbol inputs |
| GHSA-8p34-64r3-mwg8 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument |
| GHSA-c4fp-cxrr-mj66 | Net::IMAP: Denial of Service via incomplete raw argument validation |
| GHSA-46q3-7gv7-qmgg | Net::IMAP: Command Injection via ID command argument |
| GHSA-ghhp-3qvg-889p | websocket-driver: Memory exhaustion via abuse of protocol length headers |
| GHSA-33ph-fccm-39pj | websocket-driver: Resource limit bypass via message compression |
| GHSA-8j3g-f24p-4mpw | websocket-driver: Memory exhaustion in HTTP header parser |
| GHSA-28hh-pr2h-2w89 | sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity |
| GHSA-2x63-gw47-w4mm | websocket-driver-ruby: Denial of service via malformed Host header |
Data from Homebrew/advisory-database. Run brew vulns mailcatcher for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 27 | 77 | 515 |
| Installs on Request | 27 | 77 | 515 |
| Build Errors | 0 |