CVE-2026-55558
Reported by GitHub_M · Published August 20, 2026
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the plaintext 220 response in the same network segment. The method then calls loop.start_tls; those bytes survive the transport upgrade and are parsed as the first response from inside the TLS session, desynchronizing subsequent SMTP command and response pairs. Connections using start_tls=True or opportunistic STARTTLS are affected, while connections using use_tls=True are not. This issue is fixed in version 5.1.2.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cole | aiosmtplib | < 5.1.2 |
| PyPI | aiosmtplib | 0 |
| chainguard | airflow-2 | 0, 0, 0 |
| cole | aiosmtplib | < 5.1.2, < 5.1.2 |
Timeline
- Aug 20, 2026 CVE Published
- Aug 22, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 3, 2026 Security Advisory
- Sep 5, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 18, 2026 CVE Updated
- Sep 24, 2026 EPSS Score
References
- https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4 x_refsource_CONFIRM
- https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9 x_refsource_MISC
- https://github.com/cole/aiosmtplib/releases/tag/v5.1.2 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-55558 advisory
- https://github.com/advisories/GHSA-vxj7-4xrp-5vr4 advisory