Junglewise Threat Intelligence

CVE-2026-42193: Plunk improper SNS signature verification in webhooks endpoint

CVE-2026-42193 · Severity: critical · CVSS 9.1 · Published 2026-05-08

Executive brief

Plunk is an open-source email platform that integrates with Amazon Web Services to manage email delivery. A security flaw allows unauthorized individuals to send fake notifications to the system, tricking it into thinking they are legitimate messages from Amazon. This could allow an attacker to disrupt email workflows, force-unsubscribe contacts, corrupt delivery analytics, and potentially increase operational costs by exhausting billing credits.

Technical details

Plunk fails to perform cryptographic signature verification on incoming Amazon Simple Notification Service (SNS) payloads at the /webhooks/sns endpoint. The application does not validate the SNS signature, the certificate URL, or the Topic ARN, leading to an improper verification of cryptographic signatures (CWE-347). A remote, unauthenticated attacker can exploit this by sending crafted JSON payloads that mimic legitimate SNS notifications. Successful exploitation allows for the spoofing of email events (such as bounces or complaints), which can trigger automated workflows, modify contact subscription statuses, and manipulate delivery metrics. The vulnerability is resolved in version 0.9.0 by implementing mandatory SNS signature verification.

Affected products

  • useplunk Plunk < 0.9.0

Timeline

  • 2026-04-20: patched: Version 0.9.0 released with signature verification
  • 2026-04-20: advisory: GitHub Security Advisory GHSA-9792-w86v-gx53 published
  • 2026-05-08: disclosed: CVE-2026-42193 published to NVD

References

Related threats