CVE-2024-34083
aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-349
- Published
- 2024-05-18
- Last modified
- 2026-03-13
Affected products
- aio-libs aiosmtpd
Weakness type
Related vulnerabilities
- CVE-2026-15387 — Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
- CVE-2026-54625 — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
- CVE-2026-50252 — Possible cache poisoning attack by mapping source port population per thread
- CVE-2026-41120 — Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous...
- CVE-2026-46342 — Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
- CVE-2026-45602 — Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
- CVE-2026-42960 — Possible cache poisoning via promiscuous records for the authority section
- CVE-2026-44572 — Next.js: Middleware / Proxy redirects can be cache-poisoned