Skip to main content
EPSS 0.4%top 68%

CVE-2026-55558: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in cole aiosmtplib

0
Medium
Published: 08/27/2026 (08/27/2026, 23:32:22 UTC)
Source: CVE Database V5
Vendor/Project: cole
Product: aiosmtplib

Description

CVE-2026-55558 is a vulnerability in aiosmtplib affecting versions prior to 5.1.2 when using STARTTLS. The issue arises because data buffered after the server's 220 go-ahead reply and before the TLS handshake is not discarded, allowing an active man-in-the-middle attacker to inject malicious response lines that are parsed as part of the encrypted session, causing desynchronization of command/response pairs. Implicit TLS connections (use_tls=True) are not affected. A fix is available in version 5.1.2.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected software

cole

aiosmtplib

Affected versions
<5.1.2
aiosmtplib
pkg:pypi/aiosmtplib
Affected versions
<5.1.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 04:34:02 UTC

Technical Analysis

When aiosmtplib upgrades a connection with STARTTLS, it reads the server's 220 reply and immediately starts the TLS handshake without discarding any buffered data. This allows an active network attacker to inject additional response lines immediately after the 220 reply, which remain buffered and are then interpreted as part of the TLS session, causing protocol desynchronization. The vulnerability affects any caller using STARTTLS (start_tls=True or start_tls=None) on versions before 5.1.2. The fix in 5.1.2 enforces discarding any buffered data after the 220 reply before the handshake, per RFC 3207 §4.2.

Potential Impact

An active man-in-the-middle attacker on the plaintext leg of a STARTTLS connection can inject malicious response lines that aiosmtplib will parse as part of the encrypted session, causing desynchronization of SMTP commands and responses. This could lead to injection attacks or disruption of the SMTP protocol flow. Passive eavesdroppers cannot exploit this vulnerability. Connections using implicit TLS are not affected.

Mitigation Recommendations

Upgrade aiosmtplib to version 5.1.2 or later, which includes a fix that discards any buffered data after the 220 STARTTLS reply before the TLS handshake. If immediate upgrade is not possible, use implicit TLS connections by setting use_tls=True to avoid the plaintext phase entirely. Alternatively, restrict STARTTLS connections to servers on trusted network paths to reduce risk from active network attackers.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-16T23:11:20.213Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a871151acd9273b49bdeee2

Added to database: 08/20/2026, 14:38:09 UTC

Last enriched: 09/11/2026, 04:34:02 UTC

Last updated: 10/04/2026, 16:08:39 UTC

Views: 62

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses