Answer in brief
CVE-2026-55558 records a Medium severity (CVSS 5.9) vulnerability in aiosmtplib: STARTTLS response injection. The current sources do not mark it as known exploited. The current feed maps cole/aiosmtplib (generic), aiosmtplib (pip), aiosmtplib (pypi). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps cole/aiosmtplib (generic), aiosmtplib (pip), aiosmtplib (pypi). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| cole/aiosmtplibgeneric | <5.1.2 | 5.1.2 |
| aiosmtplibpip | <=5.1.1 | 5.1.2 |
| aiosmtplibpypi | >=0 <5.1.2 | 5.1.2 |
Published upstream
Aug 20, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 18, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 20, 2026
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the plaintext 220 response in the same network segment. The method then calls loop.start_tls; those bytes survive the transport upgrade and are parsed as the first response from inside the TLS session, desynchronizing subsequent SMTP command and response pairs. Connections using start_tls=True or opportunistic STARTTLS are affected, while connections using use_tls=True are not. This issue is fixed in version 5.1.2.
Quoted source text, attributed separately from HOL analysis.