CVE-2026-90467

NameCVE-2026-90467
Descriptionaiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147474

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
aiosmtplib (PTS)bookworm2.0.0-1vulnerable
trixie4.0.0-1vulnerable
forky, sid5.1.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aiosmtplibsource(unstable)5.1.3-11147474

Notes

[trixie] - aiosmtplib <no-dsa> (Minor issue)
[bookworm] - aiosmtplib <postponed> (Minor issue)
Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)

Search for package or bug name: Reporting problems