THREAT OPS › Threat News › [GHSA] GHSA-vxj7-4xrp-5vr4 (medium) — aiosmtplib: STARTTLS response injection
[GHSA] GHSA-vxj7-4xrp-5vr4 (medium) — aiosmtplib: STARTTLS response injection
GHSA-vxj7-4xrp-5vr4 Severity: medium CVE: CVE-2026-55558
aiosmtplib: STARTTLS response injection
## Impact
When a connection is upgraded with STARTTLS, aiosmtplib reads the server's 220 go-ahead reply and immediately performs the TLS handshake without discarding any data still sitting in the receive buffer. Bytes the protocol read off the plaintext socket before the handshake survive across the
Indicators of compromise
- CVE-2026-55558cve
Original source: https://github.com/advisories/GHSA-vxj7-4xrp-5vr4