chore(deps): update dependency aiosmtplib to v5.1.1 [security] #29
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/pypi-aiosmtplib-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
5.1.0→5.1.1aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
CVE-2026-53533 / GHSA-v3q9-hj7j-63hq / PYSEC-2026-2338
More information
Details
Summary
aiosmtplib'sSMTP.mail(),SMTP.rcpt(),SMTP.vrfy()andSMTP.expn()send the caller-supplied email address to the server without rejecting embedded CR/LF (\r\n) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more additional, standalone SMTP command lines. A caller that passes an attacker-influenced sender or recipient address intomail()/rcpt()(orvrfy()/expn()) therefore allows SMTP command injection (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such asMAIL FROM,RCPT TO,RSET,DATA, orAUTHinto the session. Injected commands will cause theSMTPinstance to hang, but all commands required to complete the envelope could be sent in one address string.The
SMTP.sendmail()command will pass sender and recipient addresses verbatim through toSMTP.mail()&SMTP.rcpt(), and so is also vulnerable.SMTP.send_message()is not affected.Impact
Severity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection).
When an application built on
aiosmtplibderives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it tomail()/rcpt()(directly, or viasendmail()/send()without aMessageobject), the attacker can:The address only needs to reach
mail()/rcpt()/vrfy()/expn(); no attacker control over the SMTP server is required.Vulnerable versions
Affected version:
aiosmtplib5.1.0 (latest at time of report) and all earlier releases.Credit
Reported by tonghuaroot.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
CVE-2026-53533 / GHSA-v3q9-hj7j-63hq / PYSEC-2026-2338
More information
Details
Summary
aiosmtplib'sSMTP.mail(),SMTP.rcpt(),SMTP.vrfy()andSMTP.expn()send the caller-supplied email address to the server without rejecting embedded CR/LF (\r\n) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more additional, standalone SMTP command lines. A caller that passes an attacker-influenced sender or recipient address intomail()/rcpt()(orvrfy()/expn()) therefore allows SMTP command injection (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such asMAIL FROM,RCPT TO,RSET,DATA, orAUTHinto the session. Injected commands will cause theSMTPinstance to hang, but all commands required to complete the envelope could be sent in one address string.The
SMTP.sendmail()command will pass sender and recipient addresses verbatim through toSMTP.mail()&SMTP.rcpt(), and so is also vulnerable.SMTP.send_message()is not affected.Impact
Severity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection).
When an application built on
aiosmtplibderives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it tomail()/rcpt()(directly, or viasendmail()/send()without aMessageobject), the attacker can:The address only needs to reach
mail()/rcpt()/vrfy()/expn(); no attacker control over the SMTP server is required.Vulnerable versions
Affected version:
aiosmtplib5.1.0 (latest at time of report) and all earlier releases.Credit
Reported by tonghuaroot.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
Release Notes
cole/aiosmtplib (aiosmtplib)
v5.1.1Compare Source
0x00-0x1Fand DEL0x7F, including CR, LF, and NUL) in SMTP command arguments, preventingcommand injection via input passed to
mail(),rcpt(),vrfy(),expn()orsendmail(). Such input now raisesValueErrorbeforeanything is written to the connection.
More details: https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq
Thanks to @tonghuaroot for the report.
SMTP.quit()no longer hangs until the read timeout when thepeer drops the transport with an exception after
QUITis sent butbefore the 221 reply is parsed (e.g. AWS SES closing TLS without
close_notify).Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.