{"id":"PYSEC-2026-2338","summary":"aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address","details":"### Summary\n\n`aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\\r\\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after the CRLF are framed by the server as one or more **additional, standalone SMTP command lines**. A caller that passes an attacker-influenced sender or recipient address into `mail()`/`rcpt()` (or `vrfy()`/`expn()`) therefore allows **SMTP command injection** (CWE-93 / CWE-77): the attacker can smuggle arbitrary SMTP verbs such as `MAIL FROM`, `RCPT TO`, `RSET`, `DATA`, or `AUTH` into the session. Injected commands will cause the `SMTP` instance to hang, but all commands required to complete the envelope could be sent in one address string.\n\nThe `SMTP.sendmail()` command will pass sender and recipient addresses verbatim through to `SMTP.mail()` & `SMTP.rcpt()`, and so is also vulnerable. `SMTP.send_message()` is not affected.\n\n### Impact\n\nSeverity: medium. Type: SMTP protocol command injection (CWE-93 — Improper Neutralization of CRLF Sequences; CWE-77 — Command Injection).\n\nWhen an application built on `aiosmtplib` derives the envelope sender or any recipient from data an attacker can influence (a web form etc.) and passes it to `mail()`/`rcpt()` (directly, or via `sendmail()`/`send()` without a `Message` object), the attacker can:\n\n- desynchronize the command/response pipeline and cause the aiosmtplib client to hang, resulting in a possible denial of service\n- inject multiple commands in one address to send an arbitrary message\n\nThe address only needs to reach `mail()`/`rcpt()`/`vrfy()`/`expn()`; no attacker control over the SMTP server is required.\n\n### Vulnerable versions\n\nAffected version: `aiosmtplib` 5.1.0 (latest at time of report) and all earlier releases.\n\n### Credit\n\nReported by tonghuaroot.","aliases":["CVE-2026-53533","GHSA-v3q9-hj7j-63hq"],"modified":"2026-07-13T16:49:05.233370500Z","published":"2026-07-13T15:46:29.471704Z","references":[{"type":"WEB","url":"https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq"},{"type":"PACKAGE","url":"https://github.com/cole/aiosmtplib"},{"type":"PACKAGE","url":"https://pypi.org/project/aiosmtplib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v3q9-hj7j-63hq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53533"}],"affected":[{"package":{"name":"aiosmtplib","ecosystem":"PyPI","purl":"pkg:pypi/aiosmtplib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1"}]}],"versions":["0.1","0.1.2","0.1.3","0.1.4","0.1.5rc2","0.1.6","0.1.7","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1b0","2.0.0","2.0.0b0","2.0.0b1","2.0.1","2.0.2","3.0.0","3.0.1","3.0.2","4.0.0","4.0.1","4.0.2","5.0.0","5.1.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/aiosmtplib/PYSEC-2026-2338.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:N"}]}