THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vxj7-4xrp-5vr4 (medium) — aiosmtplib: STARTTLS response injection

[GHSA] GHSA-vxj7-4xrp-5vr4 (medium) — aiosmtplib: STARTTLS response injection

medgithub_advisoriesPublished 2026-08-27

GHSA-vxj7-4xrp-5vr4 Severity: medium CVE: CVE-2026-55558

aiosmtplib: STARTTLS response injection

## Impact

When a connection is upgraded with STARTTLS, aiosmtplib reads the server's 220 go-ahead reply and immediately performs the TLS handshake without discarding any data still sitting in the receive buffer. Bytes the protocol read off the plaintext socket before the handshake survive across the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vxj7-4xrp-5vr4