GHSA-2pm6-9fhx-vvg3

Suggest an improvement
Source
https://github.com/advisories/GHSA-2pm6-9fhx-vvg3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2pm6-9fhx-vvg3/GHSA-2pm6-9fhx-vvg3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2pm6-9fhx-vvg3
Aliases
Published
2026-03-18T16:17:08Z
Modified
2026-05-05T15:56:07Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Details

Description

The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].

Database specific
{
    "cwe_ids": [
        "CWE-502"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-18T16:17:08Z",
    "nvd_published_at": "2026-03-17T09:16:13Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / cpsit/typo3-mailqueue

Package

Name
cpsit/typo3-mailqueue
Purl
pkg:composer/cpsit/typo3-mailqueue

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.5

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2pm6-9fhx-vvg3/GHSA-2pm6-9fhx-vvg3.json"

Packagist / cpsit/typo3-mailqueue

Package

Name
cpsit/typo3-mailqueue
Purl
pkg:composer/cpsit/typo3-mailqueue

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.5.0
Fixed
0.5.2

Affected versions

0.*
0.5.0
0.5.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2pm6-9fhx-vvg3/GHSA-2pm6-9fhx-vvg3.json"