PT-2026-95424 · Unknown · Netty-Codec-Smtp
CVE-2026-93576
·
Published
2026-09-18
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
netty-codec-smtp versions prior to 4.1.138-1.1
Description
Netty netty-codec-smtp fails to properly validate Carriage Return (CR) and Line Feed (LF) characters within the SMTP command-name field. If an application passes untrusted input into this field, a remote attacker can inject CR/LF characters to execute arbitrary SMTP commands. This leads to SMTP command smuggling, which may enable unauthorized email relay or the spoofing of sender and recipient addresses.
Recommendations
Update to version 4.1.138-1.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty-Codec-Smtp