MEDIUMVulnerability

CVE-2026-90467

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.

Properties

severity
MEDIUM
score
4
cve_id
CVE-2026-90467
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
published_at
2026-09-12T02:16:24.770
last_modified
2026-09-23T17:17:44.240

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90467 — Ninja Signal Threat Intelligence | Ninja Signal