-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper buffer handling during TLS handshake. The commit diff shows a critical addition of 'self._reader._buffer.clear()' in smtp.py's connection_made method. This indicates the vulnerable code path was processing residual unencrypted commands from the pre-TLS buffer. The CWE-349 classification and RFC 3207 reference in the commit message confirm this was a protocol compliance issue in buffer management during encryption context switching.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| aiosmtpd | pip | < 1.4.6 | 1.4.6 |
Ongoing coverage of React2Shell