CVE-2026-55558: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in cole aiosmtplib
Description
CVE-2026-55558 is a vulnerability in aiosmtplib affecting versions prior to 5.1.2 when using STARTTLS. The issue arises because data buffered after the server's 220 go-ahead reply and before the TLS handshake is not discarded, allowing an active man-in-the-middle attacker to inject malicious response lines that are parsed as part of the encrypted session, causing desynchronization of command/response pairs. Implicit TLS connections (use_tls=True) are not affected. A fix is available in version 5.1.2.
CVSS v3.1
Score 5.9medium
Affected software
cole
aiosmtplib
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
When aiosmtplib upgrades a connection with STARTTLS, it reads the server's 220 reply and immediately starts the TLS handshake without discarding any buffered data. This allows an active network attacker to inject additional response lines immediately after the 220 reply, which remain buffered and are then interpreted as part of the TLS session, causing protocol desynchronization. The vulnerability affects any caller using STARTTLS (start_tls=True or start_tls=None) on versions before 5.1.2. The fix in 5.1.2 enforces discarding any buffered data after the 220 reply before the handshake, per RFC 3207 §4.2.
Potential Impact
An active man-in-the-middle attacker on the plaintext leg of a STARTTLS connection can inject malicious response lines that aiosmtplib will parse as part of the encrypted session, causing desynchronization of SMTP commands and responses. This could lead to injection attacks or disruption of the SMTP protocol flow. Passive eavesdroppers cannot exploit this vulnerability. Connections using implicit TLS are not affected.
Mitigation Recommendations
Upgrade aiosmtplib to version 5.1.2 or later, which includes a fix that discards any buffered data after the 220 STARTTLS reply before the TLS handshake. If immediate upgrade is not possible, use implicit TLS connections by setting use_tls=True to avoid the plaintext phase entirely. Alternatively, restrict STARTTLS connections to servers on trusted network paths to reduce risk from active network attackers.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:11:20.213Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a871151acd9273b49bdeee2
Added to database: 08/20/2026, 14:38:09 UTC
Last enriched: 09/11/2026, 04:34:02 UTC
Last updated: 10/04/2026, 16:08:39 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.