---
id: CVE-2026-55558
title: aiosmtplib is an asynchronous SMTP client for use with asyncio
summary: >-
  aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to
  5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the
  server's 220 response and starts the TLS handshake without clearing
  SMTPProtocol._buffer. A…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-74
vendor: aiosmtplib
product: aiosmtplib
affected:
  - aiosmtplib < 5.1.2
patched:
  - aiosmtplib 5.1.2
published: '2026-08-20'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:09:01.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55558'
references:
  - url: >-
      https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9
    label: security-advisories@github.com
  - url: 'https://github.com/cole/aiosmtplib/releases/tag/v5.1.2'
    label: security-advisories@github.com
  - url: 'https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4'
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55558'
  - url: 'https://github.com/cole/aiosmtplib'
  - url: 'https://pypi.org/project/aiosmtplib'
  - url: 'https://github.com/advisories/GHSA-vxj7-4xrp-5vr4'
tags:
  - nvd
  - osv
  - pip
  - ghsa
epss: 0.00261
epssPercentile: 0.18137
aliases:
  - GHSA-vxj7-4xrp-5vr4
  - PYSEC-2026-3805
ecosystem: pip
ingestedAt: '2026-08-28T00:10:15.071Z'
---

## Overview

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the plaintext 220 response in the same network segment. The method then calls loop.start_tls; those bytes survive the transport upgrade and are parsed as the first response from inside the TLS session, desynchronizing subsequent SMTP command and response pairs. Connections using start_tls=True or opportunistic STARTTLS are affected, while connections using use_tls=True are not. This issue is fixed in version 5.1.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55558)

Affected packages:

- `aiosmtplib < 5.1.2`

Patched in:

- `aiosmtplib 5.1.2`

Source: https://osv.dev/vulnerability/GHSA-vxj7-4xrp-5vr4
