CVE-2026-54649: punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To

Published Sep 17, 2026
·
Updated

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent sends mail to an alias and the operator replies, the mail client can send directly to the correspondent from the private FORWARDTO inbox address, exposing that address. The disclosure is limited to the operator's own email address and does not expose third-party data or provide code execution or authentication bypass. This issue is fixed in version 1.5.0.

Affected Software

1 affected component
punchin-email<1.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade punchin-email to a version that resolves this vulnerability.

    Fixed in 1.5.0

Event History

Sep 17, 2026
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Operators using punchin-email versions prior to 1.5.0 who receive alias mail and reply from their private FORWARD_TO inbox are exposed. Correspondents receiving those replies may see the operator's private inbox address.

2

What user action is needed for the address disclosure to occur?

A correspondent must first send mail to an alias, and the operator must reply to that message. The reply can then be sent directly from the private FORWARD_TO address because the relay Reply-To header was dropped.

3

Does this expose other data or enable account compromise?

No. The disclosure is limited to the operator's own email address; the provided information does not indicate exposure of third-party data, code execution, or authentication bypass.

4

What version resolves the issue?

Upgrade punchin-email to version 1.5.0, which fixes the Reply-To handling issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203