Source: aiosmtplib Version: 5.1.2-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for aiosmtplib. CVE-2026-90467[0]: | aiosmtplib before 5.1.3 fails to properly validate email addresses | supplied by callers, allowing attackers to inject ESMTP parameters | into MAIL FROM and RCPT TO command lines. Attackers can craft | malicious addresses containing spaces and angle brackets to append | parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging | authenticated identities or forcing delivery notifications to third | parties. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90467 https://www.cve.org/CVERecord?id=CVE-2026-90467 [1] https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

