<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:33:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-4353</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4353</link>
      <description>EUVD-2026-4353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4353</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27305</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27305</link>
      <description>&lt;p&gt;aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27305</guid>
    </item>
    <item>
      <title>GHSA-pr2m-px7j-xg65 — aiosmtpd vulnerable to SMTP smuggling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pr2m-px7j-xg65</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiosmtpd&lt;/p&gt;
&lt;p&gt;### Summary
aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue also existed in other SMTP software like Postfix (https://www.postfix.org/smtp-smuggling.html).&lt;/p&gt;
&lt;p&gt;### Details
Detailed information on SMTP smuggling can be found in the full blog post (https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/) or on the Postfix homepage (https://www.postfix.org/smtp-smuggling.html). (and soon on the official website https://smtpsmuggling.com/)&lt;/p&gt;
&lt;p&gt;### Impact
With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiosmtpd&lt;/p&gt;
&lt;p&gt;### Summary
aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue also existed in other SMTP software like Postfix (https://www.postfix.org/smtp-smuggling.html).&lt;/p&gt;
&lt;p&gt;### Details
Detailed information on SMTP smuggling can be found in the full blog post (https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/) or on the Postfix homepage (https://www.postfix.org/smtp-smuggling.html). (and soon on the official website https://smtpsmuggling.com/)&lt;/p&gt;
&lt;p&gt;### Impact
With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pr2m-px7j-xg65</guid>
    </item>
    <item>
      <title>gsd-2024-27305</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27305</link>
      <description>gsd-2024-27305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27305</guid>
    </item>
    <item>
      <title>OESA-2024-1276 — python-aiosmtpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1276</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: python-aiosmtpd&lt;/p&gt;
&lt;p&gt;This is a server for SMTP and related protocols, similar in utility to the standard library&amp;amp;apos;s smtpd.py module, but rewritten to be based on asyncio for Python 3.&#13;
&#13;
Security Fix(es):&#13;
&#13;
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.(CVE-2024-27305)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: python-aiosmtpd&lt;/p&gt;
&lt;p&gt;This is a server for SMTP and related protocols, similar in utility to the standard library&amp;amp;apos;s smtpd.py module, but rewritten to be based on asyncio for Python 3.&#13;
&#13;
Security Fix(es):&#13;
&#13;
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.(CVE-2024-27305)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1276</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0243-1 — Security update for python-aiosmtpd</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0243-1</link>
      <description>&lt;p&gt;Security update for python-aiosmtpd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-aiosmtpd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0243-1</guid>
    </item>
    <item>
      <title>PYSEC-2024-221</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-221</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiosmtpd&lt;/p&gt;
&lt;p&gt;aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiosmtpd&lt;/p&gt;
&lt;p&gt;aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-221</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-27305</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27305</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: python-aiosmtpd, Ubuntu:20.04:LTS: python-aiosmtpd, Ubuntu:22.04:LTS: python-aiosmtpd, Ubuntu:24.04:LTS: python-aiosmtpd, Ubuntu:25.10: python-aiosmtpd, Ubuntu:26.04:LTS: python-aiosmtpd&lt;/p&gt;
&lt;p&gt;aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: python-aiosmtpd, Ubuntu:20.04:LTS: python-aiosmtpd, Ubuntu:22.04:LTS: python-aiosmtpd, Ubuntu:24.04:LTS: python-aiosmtpd, Ubuntu:25.10: python-aiosmtpd, Ubuntu:26.04:LTS: python-aiosmtpd&lt;/p&gt;
&lt;p&gt;aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27305</guid>
    </item>
  </channel>
</rss>
