MailKit
MailKit is an Open Source cross-platform .NET mail-client library that is based on MimeKit and optimized for mobile devices. Features include: * HTTP, Socks4, Socks4a and Socks5 proxy support. * SASL Authentication via ANONYMOUS, CRAM-MD5, DIGEST-MD5, LOGIN, NTLM, OAUTHBEARER, PLAIN, SCRAM-SHA-1, SCRAM-SHA-256, SCRAM-SHA-512 and XOAUTH2. * A fully-cancellable SmtpClient with support for STARTTLS, 8BITMIME, BINARYMIME, ENHANCEDSTATUSCODES, SIZE, DSN, PIPELINING and SMTPUTF8. * A fully-cancellable Pop3Client with support for STLS, UIDL, APOP, PIPELINING, UTF8, and LANG. * A fully-cancellable ImapClient with support for ACL, QUOTA, LITERAL+, IDLE, NAMESPACE, ID, CHILDREN, LOGINDISABLED, STARTTLS, MULTIAPPEND, UNSELECT, UIDPLUS, CONDSTORE, ESEARCH, SASL-IR, COMPRESS, WITHIN, ENABLE, QRESYNC, SORT, THREAD, ANNOTATE, LIST-EXTENDED, ESORT, METADATA / METADATA-SERVER, NOTIFY, FILTERS, LIST-STATUS, SORT=DISPLAY, SPECIAL-USE / CREATE-SPECIAL-USE, SEARCH=FUZZY, MOVE, UTF8=ACCEPT / UTF8=ONLY, LITERAL-, APPENDLIMIT, STATUS=SIZE, OBJECTID, REPLACE, SAVEDATE, XLIST, and X-GM-EXT1. * Client-side sorting and threading of messages (the Ordinal Subject and the Jamie Zawinski threading algorithms are supported). * Asynchronous versions of all methods that hit the network. * S/MIME, OpenPGP, DKIM and ARC support via MimeKit. * Microsoft TNEF support via MimeKit.
Activity
- Latest release
- 11h ago
- Total releases
- 85
- Cadence
- ~42 days
- Last 12 months
- 6
Details
- License
- MIT
- First release
- Oct 31, 2016
| Version | Released | |
|---|---|---|
4.18.0
minor
|
4.18.0
minor
Dependencies (3)
|
|
4.17.0
minor
|
4.17.0
minor
Dependencies (3)
|
|
4.16.0
minor
|
4.16.0
minor
Dependencies (3)
|
|
4.15.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.15.1
patch
Dependencies (3)
|
|
4.15.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.15.0
minor
Dependencies (3)
|
|
4.14.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.14.1
patch
Dependencies (3)
|
|
4.14.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.14.0
minor
Dependencies (3)
|
|
4.13.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.13.0
minor
Dependencies (3)
|
|
4.12.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.12.1
patch
Dependencies (3)
|
|
4.12.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.12.0
minor
Dependencies (3)
|
|
4.11.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.11.0
minor
Dependencies (3)
|
|
4.10.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.10.0
minor
Dependencies (3)
|
|
4.9.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.9.0
minor
Dependencies (3)
|
|
4.8.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.8.0
minor
Dependencies (3)
|
|
4.7.1.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.7.1.1
patch
Dependencies (3)
|
|
4.7.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.7.1
patch
Dependencies (3)
|
|
4.7.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.7.0
minor
Dependencies (3)
|
|
4.6.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.6.0
minor
Dependencies (3)
|
|
4.5.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.5.0
minor
Dependencies (3)
|
|
4.4.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.4.0
minor
Dependencies (3)
|
|
4.3.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.3.0
minor
Dependencies (3)
|
|
4.2.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.2.0
minor
Dependencies (3)
|
|
4.1.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.1.0
minor
Dependencies (3)
|
|
4.0.0
major
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
4.0.0
major
Dependencies (2)
|
|
3.6.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.6.0
minor
Dependencies (2)
|
|
3.5.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.5.0
minor
Dependencies (2)
|
|
3.4.3
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.4.3
patch
Dependencies (2)
|
|
3.4.2
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.4.2
patch
Dependencies (2)
|
|
3.4.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.4.1
patch
Dependencies (2)
|
|
3.4.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.4.0
minor
Dependencies (2)
|
|
3.3.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (2)
|
|
3.2.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (2)
|
|
3.1.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (1)
|
|
3.1.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (1)
|
|
3.0.0
major
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (1)
|
|
2.15.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.15.0
minor
Dependencies (1)
|
|
2.14.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.14.0
minor
Dependencies (1)
|
|
2.13.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.13.0
minor
Dependencies (1)
|
|
2.12.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.12.0
minor
Dependencies (1)
|
|
2.11.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.11.1
patch
Dependencies (1)
|
|
2.11.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.11.0
minor
Dependencies (1)
|
|
2.10.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.10.1
patch
Dependencies (1)
|
|
2.10.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.10.0
minor
Dependencies (1)
|
|
2.9.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.9.0
minor
Dependencies (4)
|
|
2.8.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.8.0
minor
Dependencies (4)
|
|
2.7.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (4)
|
|
2.6.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (4)
|
|
2.5.2
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (4)
|
|
2.5.1
patch
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (4)
|
|
2.5.0
minor
1 CVE
CVE-2026-41319
GHSA-9j88-vvj5-vhgr
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
SummaryA STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in DetailsThe
During the STARTTLS upgrade in
A MitM appends extra data after the The same pattern exists in Attack flow:
Suggested fix: Reset buffer indices when the stream is replaced:
PoCSelf-contained C# PoC — creates a fake SMTP server that injects a crafted EHLO response into the STARTTLS reply:
Result against MailKit 4.12.0:
ImpactAny application using MailKit with Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.19.0
0.2.0
+ 176 more Show less
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.90.0
0.90.0.1
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.6.1
1.0.7
1.0.8
1.0.9
1.10.0
1.10.1
1.10.2
1.12.0
1.14.0
1.14.1
1.14.2
1.16.0
1.16.1
1.16.2
1.18.0
1.18.1
1.18.1.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.11.1
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16-beta1
1.2.16-beta2
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.20.0
1.22.0
1.3.0-beta1
1.3.0-beta2
1.3.0-beta3
1.3.0-beta4
1.3.0-beta5
1.3.0-beta6
1.3.0-beta7
1.3.0-rc1
1.3.0-rc1-1
1.4.0
1.4.1
1.4.2
1.4.2.1
1.6.0
1.8.0
1.8.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.0.1
2.1.0.2
2.1.0.3
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.5.1
2.10.0
2.10.1
2.11.0
2.11.1
2.12.0
2.13.0
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.1.6
2.3.2
2.4.0
2.4.0.1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0-preview1
3.1.0
3.1.1
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.6.0
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.15.0
4.15.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.7.1.1
4.8.0
4.9.0
Fixed in
4.16.0
References Updated May 05, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (4)
|