Description
aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.
Published: 2026-09-12
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: ESMTP parameter injection enabling forged identities and unauthorized notification handling
Action: Patch
AI Analysis

Impact

aiosmtplib is a Python library that sends email via SMTP. In versions prior to 5.1.3 it does not validate email address inputs that are supplied to the MAIL FROM and RCPT TO commands. Attackers can craft addresses containing spaces and angle brackets to embed ESMTP parameters such as AUTH, NOTIFY, or ORCPT, allowing them to forge a sender identity or redirect delivery notifications to arbitrary third parties. execution but compromises the integrity of email delivery and can be used for spoofing and notification abuse.

Affected Systems

The product aiosmtplib, maintained by cole, is vulnerable in all releases before version 5.1.3. The fix that sanitizes address inputs is available in v5.1.3 and later.

Risk and Exploitability

The moderate CVSS score of 6.3 indicates that the vulnerability mainly impacts integrity. The EPSS score of less than 1 % and the fact that it is not listed in the CISA KEV suggest that exploitation is unlikely to be widespread. The likely attack vector requires only the ability to invoke the library with a crafted address; no additional privileges or network access beyond normal SMTP usage appear to be necessary.

Generated by OpenCVE AI on September 15, 2026 at 19:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade aiosmtplib to version 5.1.3 or later, which includes address sanitization.
  • Implement strict validation of email address inputs in your application before passing them to aiosmtplib, rejecting any characters that could form ESMTP parameters.
  • Deploy monitoring that logs outgoing SMTP envelope commands and configure your SMTP server to reject or quarantine messages containing unexpected ESMTP parameters.

Generated by OpenCVE AI on September 15, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Cole
Cole aiosmtplib
Vendors & Products Cole
Cole aiosmtplib

Sat, 12 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.
Title aiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addresses
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:17:05.398Z

Reserved: 2026-09-11T23:36:20.310Z

Link: CVE-2026-90467

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:46.987Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T02:16:24.770

Modified: 2026-09-23T17:17:44.240

Link: CVE-2026-90467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')