CVE-2026-90467: aiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addresses

Published Sep 12, 2026
·
Updated

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.

Affected Software

1 affected component
pypi/aiosmtplib<5.1.3

Event History

Sep 12, 2026
CVE Published
via MITRE·01:50 AM
Data Sourced
via MITRE·01:50 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using aiosmtplib before 5.1.3 are exposed when untrusted parties can influence the email addresses passed by the application as envelope sender or recipient values.

2

What must an attacker control to exploit it?

An attacker needs to supply a crafted email address containing spaces and angle brackets. This can append ESMTP parameters to MAIL FROM or RCPT TO command lines.

3

What is the recommended remediation?

Upgrade aiosmtplib to version 5.1.3 or later. The affected versions are those before 5.1.3.

4

What can be done if upgrading is not immediately possible?

Ensure that caller-supplied envelope addresses are validated before being passed to aiosmtplib, rejecting values that contain spaces or angle brackets capable of adding SMTP command parameters.

5

How can an organization investigate possible exploitation?

Review application inputs and SMTP transaction logs for MAIL FROM or RCPT TO commands containing unexpected parameters such as AUTH, NOTIFY, or ORCPT, especially where those values originated from user-controlled address fields.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203