aiosmtplib
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting aiosmtplibpage 1 of 1
- CVE-2026-53533MEDIUMCVSS 6.9EG 6.9✓ Fixed in 5.1.12026-07-07
vulnerable: 0.1 ... 5.1.0 (36 versions)
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is f…
- CVE-2026-55558MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.1.22026-08-20
vulnerable: 0.1 ... 5.1.1 (37 versions)
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An …
Check whether aiosmtplib is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for aiosmtplib CVEs against the assets you own.
Start Free Scan →