HIGH8.8
GHSA-2pm6-9fhx-vvg3
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Quick fix
GHSA-2pm6-9fhx-vvg3 — cpsit/typo3-mailqueue: upgrade to the fixed version with the command below.
composer require cpsit/typo3-mailqueue:^0.4.5Details
## Description
The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at `$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath']`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cpsit/typo3-mailqueue
Introduced in:
0Fixed in: 0.4.5Fix
composer require cpsit/typo3-mailqueue:^0.4.5Packagist/cpsit/typo3-mailqueue
Introduced in:
0.5.0Fixed in: 0.5.2Fix
composer require cpsit/typo3-mailqueue:^0.5.2References
- https://github.com/CPS-IT/mailqueue/security/advisories/GHSA-2pm6-9fhx-vvg3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-1323[ADVISORY]
- https://github.com/CPS-IT/mailqueue/commit/0f7a1376bbbd8c7658030d02e51c10a85b1dfdf7[WEB]
- https://github.com/CPS-IT/mailqueue/commit/600c7dba99f8eea5f2505b848ee3dd4713440741[WEB]
- https://github.com/CPS-IT/mailqueue[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2026-005[WEB]