<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:03:24.227974+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5416</id>
    <title>EUVD-2026-5416</title>
    <updated>2026-10-08T08:03:24.233544+00:00</updated>
    <content>EUVD-2026-5416</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5416"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-34083</id>
    <title>fkie_cve-2024-34083</title>
    <updated>2026-10-08T08:03:24.233576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>aiosmptd is  a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-34083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wgjv-9j3q-jhg8</id>
    <title>GHSA-wgjv-9j3q-jhg8 — aiosmtpd STARTTLS unencrypted commands injection</title>
    <updated>2026-10-08T08:03:24.233606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiosmtpd</p>
<p>### Summary
Servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a MitM attack.</p>
<p>### References
* [NO STARTTLS: Similar vulnerabilities discovered by previous researchers.](https://nostarttls.secvuln.info/)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wgjv-9j3q-jhg8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1695</id>
    <title>OESA-2024-1695 — python-aiosmtpd security update</title>
    <updated>2026-10-08T08:03:24.233631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: python-aiosmtpd</p>
<p>This is a server for SMTP and related protocols, similar in utility to the standard library&amp;apos;s smtpd.py module, but rewritten to be based on asyncio for Python 3.

Security Fix(es):

aiosmptd is  a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.(CVE-2024-34083)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0243-1</id>
    <title>openSUSE-SU-2024:0243-1 — Security update for python-aiosmtpd</title>
    <updated>2026-10-08T08:03:24.233654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-aiosmtpd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0243-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1111</id>
    <title>PYSEC-2026-1111 — aiosmtpd STARTTLS unencrypted commands injection</title>
    <updated>2026-10-08T08:03:24.233670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiosmtpd</p>
<p>### Summary
Servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a MitM attack.</p>
<p>### References
* [NO STARTTLS: Similar vulnerabilities discovered by previous researchers.](https://nostarttls.secvuln.info/)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-34083</id>
    <title>UBUNTU-CVE-2024-34083</title>
    <updated>2026-10-08T08:03:24.233687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: python-aiosmtpd, Ubuntu:20.04:LTS: python-aiosmtpd, Ubuntu:22.04:LTS: python-aiosmtpd, Ubuntu:24.04:LTS: python-aiosmtpd, Ubuntu:25.10: python-aiosmtpd, Ubuntu:26.04:LTS: python-aiosmtpd</p>
<p>aiosmptd is  a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-34083"/>
  </entry>
</feed>
