VDB
Sign up
MEDIUM5.4

PYSEC-2026-1111

aiosmtpd STARTTLS unencrypted commands injection

Quick fix

PYSEC-2026-1111 — aiosmtpd: upgrade to the fixed version with the command below.

pip install --upgrade 'aiosmtpd>=1.4.6'

Details

### Summary Servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a MitM attack.

### References * [NO STARTTLS: Similar vulnerabilities discovered by previous researchers.](https://nostarttls.secvuln.info/)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aiosmtpd
Introduced in: 0Fixed in: 1.4.6
Fixpip install --upgrade 'aiosmtpd>=1.4.6'

References