GHSA-ggff-9mj3-7246

Suggest an improvement
Source
https://github.com/advisories/GHSA-ggff-9mj3-7246
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-ggff-9mj3-7246/GHSA-ggff-9mj3-7246.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ggff-9mj3-7246
Aliases
Published
2026-01-21T15:47:44Z
Modified
2026-02-03T03:10:05.271890Z
Severity
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Details

Description

The extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension.

More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004.

References

  • TYPO3-EXT-SA-2026-001
  • https://github.com/CPS-IT/mailqueue/commit/fd09aa4e1a751551bae4b228bee814e22f2048db
  • https://github.com/CPS-IT/mailqueue/commit/12a0a35027bb5609917790a94e43bbf117abf733
Database specific
{
    "github_reviewed_at": "2026-01-21T15:47:44Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-502"
    ],
    "nvd_published_at": "2026-01-20T08:16:01Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / cpsit/typo3-mailqueue

Package

Name
cpsit/typo3-mailqueue
Purl
pkg:composer/cpsit/typo3-mailqueue

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.3

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-ggff-9mj3-7246/GHSA-ggff-9mj3-7246.json"

Packagist / cpsit/typo3-mailqueue

Package

Name
cpsit/typo3-mailqueue
Purl
pkg:composer/cpsit/typo3-mailqueue

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.5.0
Fixed
0.5.1

Affected versions

0.*
0.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-ggff-9mj3-7246/GHSA-ggff-9mj3-7246.json"