VDB
Sign up
MEDIUM

GHSA-ggff-9mj3-7246

mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport

Quick fix

GHSA-ggff-9mj3-7246 — cpsit/typo3-mailqueue: upgrade to the fixed version with the command below.

composer require cpsit/typo3-mailqueue:^0.4.3

Details

## Description

The extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to [TYPO3-CORE-SA-2026-004](https://typo3.org/security/advisory/typo3-core-sa-2026-004). Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension.

More information about this vulnerability can be found in the related TYPO3 Core Security Advisory [TYPO3-CORE-SA-2026-004](https://typo3.org/security/advisory/typo3-core-sa-2026-004).

## References

* [TYPO3-EXT-SA-2026-001](https://typo3.org/security/advisory/typo3-ext-sa-2026-001) * https://github.com/CPS-IT/mailqueue/commit/fd09aa4e1a751551bae4b228bee814e22f2048db * https://github.com/CPS-IT/mailqueue/commit/12a0a35027bb5609917790a94e43bbf117abf733

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cpsit/typo3-mailqueue
Introduced in: 0Fixed in: 0.4.3
Fixcomposer require cpsit/typo3-mailqueue:^0.4.3
Packagist/cpsit/typo3-mailqueue
Introduced in: 0.5.0Fixed in: 0.5.1
Fixcomposer require cpsit/typo3-mailqueue:^0.5.1

References