CVE-2026-90467

NameCVE-2026-90467
Descriptionaiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147474

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
aiosmtplib (PTS)bookworm2.0.0-1vulnerable
trixie4.0.0-1vulnerable
forky, sid5.1.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aiosmtplibsource(unstable)(unfixed)1147474

Notes

Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)

Search for package or bug name: Reporting problems