Bien Nguyen
Oct 21, 2025
visibility 3119
star star star star star
(4 votes)

MimeKit Vulnerability and EPiServer.CMS.Core Dependency Update

Hi everyone,

We want to inform you about a critical security vulnerability affecting older versions of the EPiServer.CMS.Core package due to its indirect dependency on MimeKit 3.0.

🔍 What’s the Issue?

Versions of EPiServer.CMS.Core prior to 12.22.4 have a dependency on MailKit 3.0 up to 4.x, which in turn depends on MimeKit 3.0. Unfortunately, MimeKit 3.0 contains a high severity vulnerability, the patch version is 4.7.1.

✅ What We Did

Starting from EPiServer.CMS.Core version 12.22.4, which was released for a couple of months, we updated the dependency range for MailKit to [3.0, 5.0). This change allows you to be able to manually upgrade MailKit and MimeKit to safer versions. Specifically, we recommend upgrading the MailKit package to 4.7.1 or higher which requires the patch version of MimeKit 4.7.1 or higher.

📢 What You Should Do

We strongly advise:

  1. Upgrade EPiServer.CMS.Core to version 12.22.4 or later.
  2. Manually upgrade MailKit to version 4.7.1 or higher.

This will eliminate the vulnerability and align your application with best security practices.

Note: Upgrading MailKit to a new major version (v4) should not cause any issues in CMS. We have already verified compatibility when extending the dependency range in version 12.22.4.
However, if your application directly uses MailKit, please be aware that MailKit v4 introduces changes in public APIs, and you may need to update your implementation accordingly.

🔒 Looking Ahead

Security is a top priority for us. We are actively considering enforcing a higher minimum version of MailKit in future CMS Core releases to ensure all customers benefit from secure defaults.


If you have any questions, please reach out to our support team. Thank you for your continued trust and commitment to secure software practices.

Oct 21, 2025

Comments

Linda Mohacsi
Linda Mohacsi May 6, 2026 08:44 AM

The latest version of Episerver.Find.Framework (as I type that is version 16.7.1) has a transient reference to EPiServer.CMS.Core 12.21.2, which requires MailKit < 4.0.0

We added Forms to our solution but emailing from Forms did not work. No errors could be seen in the log. After a lot of troubleshooting we found that this mismatch in package dependencies was the issue.
We had to manually upgrade MailKit and MimeKit as per this article, and upgrade both EPiServer.CMS.Core and EPiServer.CMS.AspNet.Core to version 12.22.4 or later that supports MailKit >4.0.0

I hope this helps anyone troubleshooting the same issue!

The screenshot is of Find 16.7.0, but the same issue remains in version 16.7.1.

When is a version of Find that references a later version of EPiServer.CMS.Core going to be released?

error Please login to comment.
Latest blogs
Flat or Nested? Weighing Your Content Modeling Options in Optimizely SaaS CMS

When building a headless site on Optimizely SaaS CMS, one of the earliest and most critical design milestones your team will face is defining your...

Vipin Banka | Jul 31, 2026

From SDK to Core: Modernizing Optimizely Configured Commerce for .NET 8 and .NET 10

The .NET Framework 4.8 clock is running out for Configured Commerce customizations. Handled well, this deadline is not a chore it is the cleanest...

Vaibhav | Jul 29, 2026

Parallel Development in Optimizely CMS SaaS: Shifting to a Schema Migration Mindset

  Part 3 of the Parallel Development series. The branch-scoped push script from Part 1 works. Run it on a feature branch where you've touched a...

Vipin Banka | Jul 25, 2026

From AI Agents to AI Workflow with Opal

Introduction In the first article in this series , we talked about AI agents in Optimizely Opal and walked through the process of creating a...

Igor Safonov | Jul 23, 2026