GHSA-ggff-9mj3-7246
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Quick fix
GHSA-ggff-9mj3-7246 — cpsit/typo3-mailqueue: upgrade to the fixed version with the command below.
composer require cpsit/typo3-mailqueue:^0.4.3Details
## Description
The extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to [TYPO3-CORE-SA-2026-004](https://typo3.org/security/advisory/typo3-core-sa-2026-004). Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension.
More information about this vulnerability can be found in the related TYPO3 Core Security Advisory [TYPO3-CORE-SA-2026-004](https://typo3.org/security/advisory/typo3-core-sa-2026-004).
## References
* [TYPO3-EXT-SA-2026-001](https://typo3.org/security/advisory/typo3-ext-sa-2026-001) * https://github.com/CPS-IT/mailqueue/commit/fd09aa4e1a751551bae4b228bee814e22f2048db * https://github.com/CPS-IT/mailqueue/commit/12a0a35027bb5609917790a94e43bbf117abf733
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.4.3composer require cpsit/typo3-mailqueue:^0.4.30.5.0Fixed in: 0.5.1composer require cpsit/typo3-mailqueue:^0.5.1References
- https://github.com/CPS-IT/mailqueue/security/advisories/GHSA-ggff-9mj3-7246[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-0895[ADVISORY]
- https://github.com/CPS-IT/mailqueue/commit/12a0a35027bb5609917790a94e43bbf117abf733[WEB]
- https://github.com/CPS-IT/mailqueue/commit/fd09aa4e1a751551bae4b228bee814e22f2048db[WEB]
- https://github.com/CPS-IT/mailqueue[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2026-001[WEB]