chore(deps): update dependency aiosmtplib to v5.1.1 [security] #29

Merged
finkregh merged 1 commit from renovate/pypi-aiosmtplib-vulnerability into main 2026-08-05 16:31:34 +00:00
Collaborator

This PR contains the following updates:

Package Type Update Change
aiosmtplib (changelog) project.dependencies patch 5.1.0 → 5.1.1

aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address

CVE-2026-53533 / GHSA-v3q9-hj7j-63hq / PYSEC-2026-2338

More information

Details

Summary

aiosmtplib's SMTP.mail(), SMTP.rcpt(), SMTP.vrfy() and SMTP.expn() send the caller-supplied email address to the server without rejecting embedded CR/LF (\r\n) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more additional, standalone SMTP command lines. A caller that passes an attacker-influenced sender or recipient address into mail()/rcpt() (or vrfy()/expn()) therefore allows SMTP command injection (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such as MAIL FROM, RCPT TO, RSET, DATA, or AUTH into the session. Injected commands will cause the SMTP instance to hang, but all commands required to complete the envelope could be sent in one address string.

The SMTP.sendmail() command will pass sender and recipient addresses verbatim through to SMTP.mail() & SMTP.rcpt(), and so is also vulnerable. SMTP.send_message() is not affected.

Impact

Severity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection).

When an application built on aiosmtplib derives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it to mail()/rcpt() (directly, or via sendmail()/send() without a Message object), the attacker can:

  • desynchronize the command/response pipeline and cause the aiosmtplib client to hang, resulting in a possible denial of service
  • inject multiple commands in one address to send an arbitrary message

The address only needs to reach mail()/rcpt()/vrfy()/expn(); no attacker control over the SMTP server is required.

Vulnerable versions

Affected version: aiosmtplib 5.1.0 (latest at time of report) and all earlier releases.

Credit

Reported by tonghuaroot.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address

CVE-2026-53533 / GHSA-v3q9-hj7j-63hq / PYSEC-2026-2338

More information

Details

Summary

aiosmtplib's SMTP.mail(), SMTP.rcpt(), SMTP.vrfy() and SMTP.expn() send the caller-supplied email address to the server without rejecting embedded CR/LF (\r\n) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more additional, standalone SMTP command lines. A caller that passes an attacker-influenced sender or recipient address into mail()/rcpt() (or vrfy()/expn()) therefore allows SMTP command injection (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such as MAIL FROM, RCPT TO, RSET, DATA, or AUTH into the session. Injected commands will cause the SMTP instance to hang, but all commands required to complete the envelope could be sent in one address string.

The SMTP.sendmail() command will pass sender and recipient addresses verbatim through to SMTP.mail() & SMTP.rcpt(), and so is also vulnerable. SMTP.send_message() is not affected.

Impact

Severity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection).

When an application built on aiosmtplib derives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it to mail()/rcpt() (directly, or via sendmail()/send() without a Message object), the attacker can:

  • desynchronize the command/response pipeline and cause the aiosmtplib client to hang, resulting in a possible denial of service
  • inject multiple commands in one address to send an arbitrary message

The address only needs to reach mail()/rcpt()/vrfy()/expn(); no attacker control over the SMTP server is required.

Vulnerable versions

Affected version: aiosmtplib 5.1.0 (latest at time of report) and all earlier releases.

Credit

Reported by tonghuaroot.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:N

References

This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).


Release Notes

cole/aiosmtplib (aiosmtplib)

v5.1.1

Compare Source

  • Security: Reject control characters (the C0 range 0x00-0x1F and DEL
    0x7F, including CR, LF, and NUL) in SMTP command arguments, preventing
    command injection via input passed to mail(), rcpt(), vrfy(),
    expn() or sendmail(). Such input now raises ValueError before
    anything is written to the connection.
    More details: https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq
    Thanks to @​tonghuaroot for the report.
  • Bugfix: SMTP.quit() no longer hangs until the read timeout when the
    peer drops the transport with an exception after QUIT is sent but
    before the 221 reply is parsed (e.g. AWS SES closing TLS without
    close_notify).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [aiosmtplib](https://github.com/cole/aiosmtplib) ([changelog](https://github.com/cole/aiosmtplib/blob/main/CHANGELOG.rst)) | project.dependencies | patch | `5.1.0` → `5.1.1` | --- ### aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address [CVE-2026-53533](https://nvd.nist.gov/vuln/detail/CVE-2026-53533) / [GHSA-v3q9-hj7j-63hq](https://github.com/advisories/GHSA-v3q9-hj7j-63hq) / PYSEC-2026-2338 <details> <summary>More information</summary> #### Details ##### Summary `aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more **additional, standalone SMTP command lines**. A caller that passes an attacker-influenced sender or recipient address into `mail()`/`rcpt()` (or `vrfy()`/`expn()`) therefore allows **SMTP command injection** (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such as `MAIL FROM`, `RCPT TO`, `RSET`, `DATA`, or `AUTH` into the session. Injected commands will cause the `SMTP` instance to hang, but all commands required to complete the envelope could be sent in one address string. The `SMTP.sendmail()` command will pass sender and recipient addresses verbatim through to `SMTP.mail()` & `SMTP.rcpt()`, and so is also vulnerable. `SMTP.send_message()` is not affected. ##### Impact Severity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection). When an application built on `aiosmtplib` derives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it to `mail()`/`rcpt()` (directly, or via `sendmail()`/`send()` without a `Message` object), the attacker can: - desynchronize the command/response pipeline and cause the aiosmtplib client to hang, resulting in a possible denial of service - inject multiple commands in one address to send an arbitrary message The address only needs to reach `mail()`/`rcpt()`/`vrfy()`/`expn()`; no attacker control over the SMTP server is required. ##### Vulnerable versions Affected version: `aiosmtplib` 5.1.0 (latest at time of report) and all earlier releases. ##### Credit Reported by tonghuaroot. #### Severity - CVSS Score: 6.9 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:N` #### References - [https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq](https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq) - [https://github.com/cole/aiosmtplib](https://github.com/cole/aiosmtplib) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-v3q9-hj7j-63hq) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address [CVE-2026-53533](https://nvd.nist.gov/vuln/detail/CVE-2026-53533) / [GHSA-v3q9-hj7j-63hq](https://github.com/advisories/GHSA-v3q9-hj7j-63hq) / PYSEC-2026-2338 <details> <summary>More information</summary> #### Details ##### Summary `aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more **additional, standalone SMTP command lines**. A caller that passes an attacker-influenced sender or recipient address into `mail()`/`rcpt()` (or `vrfy()`/`expn()`) therefore allows **SMTP command injection** (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such as `MAIL FROM`, `RCPT TO`, `RSET`, `DATA`, or `AUTH` into the session. Injected commands will cause the `SMTP` instance to hang, but all commands required to complete the envelope could be sent in one address string. The `SMTP.sendmail()` command will pass sender and recipient addresses verbatim through to `SMTP.mail()` & `SMTP.rcpt()`, and so is also vulnerable. `SMTP.send_message()` is not affected. ##### Impact Severity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection). When an application built on `aiosmtplib` derives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it to `mail()`/`rcpt()` (directly, or via `sendmail()`/`send()` without a `Message` object), the attacker can: - desynchronize the command/response pipeline and cause the aiosmtplib client to hang, resulting in a possible denial of service - inject multiple commands in one address to send an arbitrary message The address only needs to reach `mail()`/`rcpt()`/`vrfy()`/`expn()`; no attacker control over the SMTP server is required. ##### Vulnerable versions Affected version: `aiosmtplib` 5.1.0 (latest at time of report) and all earlier releases. ##### Credit Reported by tonghuaroot. #### Severity - CVSS Score: 6.9 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:N` #### References - [https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq](https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq) - [https://github.com/cole/aiosmtplib](https://github.com/cole/aiosmtplib) - [https://pypi.org/project/aiosmtplib](https://pypi.org/project/aiosmtplib) - [https://github.com/advisories/GHSA-v3q9-hj7j-63hq](https://github.com/advisories/GHSA-v3q9-hj7j-63hq) - [https://nvd.nist.gov/vuln/detail/CVE-2026-53533](https://nvd.nist.gov/vuln/detail/CVE-2026-53533) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-2338) and the [PyPI Advisory Database](https://github.com/pypa/advisory-database) ([CC-BY 4.0](https://github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### Release Notes <details> <summary>cole/aiosmtplib (aiosmtplib)</summary> ### [`v5.1.1`](https://github.com/cole/aiosmtplib/blob/HEAD/CHANGELOG.rst#511) [Compare Source](https://github.com/cole/aiosmtplib/compare/v5.1.0...v5.1.1) - Security: Reject control characters (the C0 range `0x00`-`0x1F` and DEL `0x7F`, including CR, LF, and NUL) in SMTP command arguments, preventing command injection via input passed to `mail()`, `rcpt()`, `vrfy()`, `expn()` or `sendmail()`. Such input now raises `ValueError` before anything is written to the connection. More details: <https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq> Thanks to [@&#8203;tonghuaroot](https://github.com/tonghuaroot) for the report. - Bugfix: `SMTP.quit()` no longer hangs until the read timeout when the peer drops the transport with an exception after `QUIT` is sent but before the 221 reply is parsed (e.g. AWS SES closing TLS without `close_notify`). </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43LjAiLCJ1cGRhdGVkSW5WZXIiOiI0NC43LjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Commenting is not possible because the repository is archived.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
finkregh/verleihnix!29
No description provided.