Skip to main content

Insufficient Verification of Data Authenticity


Severity Medium
Score 5.3/10


The package aiosmtpd is a reimplementation of the Python stdlib "" based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue also exists in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue affects aiosmtpd versions prior to 1.4.5.

  • LOW
  • LOW
  • NONE
  • NONE
  • NONE
  • NONE

CWE-345 - Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.


Advisory Timeline

  • Published