{"id":"CVE-2026-55558","title":"aiosmtplib is an asynchronous SMTP client for use with asyncio","summary":"aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. A…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-74"],"vendor":"aiosmtplib","product":"aiosmtplib","affected":["aiosmtplib < 5.1.2"],"patched":["aiosmtplib 5.1.2"],"published":"2026-08-20","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:09:01.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55558","references":[{"url":"https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9","label":"security-advisories@github.com"},{"url":"https://github.com/cole/aiosmtplib/releases/tag/v5.1.2","label":"security-advisories@github.com"},{"url":"https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55558"},{"url":"https://github.com/cole/aiosmtplib"},{"url":"https://pypi.org/project/aiosmtplib"},{"url":"https://github.com/advisories/GHSA-vxj7-4xrp-5vr4"}],"tags":["nvd","osv","pip","ghsa"],"epss":0.00261,"epssPercentile":0.18102,"aliases":["GHSA-vxj7-4xrp-5vr4","PYSEC-2026-3805"],"ecosystem":"pip","ingestedAt":"2026-08-28T00:10:15.071Z","slug":"CVE-2026-55558","body":"## Overview\n\naiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the plaintext 220 response in the same network segment. The method then calls loop.start_tls; those bytes survive the transport upgrade and are parsed as the first response from inside the TLS session, desynchronizing subsequent SMTP command and response pairs. Connections using start_tls=True or opportunistic STARTTLS are affected, while connections using use_tls=True are not. This issue is fixed in version 5.1.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55558)\n\nAffected packages:\n\n- `aiosmtplib < 5.1.2`\n\nPatched in:\n\n- `aiosmtplib 5.1.2`\n\nSource: https://osv.dev/vulnerability/GHSA-vxj7-4xrp-5vr4","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}