cpsit/typo3-mailqueue
TYPO3 CMS extension to improve TYPO3's mail spooler with additional components
Activity
- Latest release
- Jun 15, 2026
- Total releases
- 19
- Cadence
- ~daily
- Last 12 months
- 7
Reach
- Stars
- 5
Details
- License
- unknown
- First release
- Mar 05, 2024
| Version | Released | |
|---|---|---|
0.6.0
minor
|
0.6.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.5.2
patch
|
0.5.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.4.5
patch
|
0.4.5
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.4.4
patch
1 CVE
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev |
0.5.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.4.2
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev |
0.4.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.4.1
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev |
0.4.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.3.2
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev |
0.3.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.3.1
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev |
0.3.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.3.0
minor
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.1.3
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2026-1323
GHSA-2pm6-9fhx-vvg3
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Medium
Local
Low
Low
None
DescriptionThe extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 4 more Show less
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.4.5
0.5.2
References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-0895
GHSA-ggff-9mj3-7246
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Medium
Local
Low
Low
None
DescriptionThe extension extends TYPO3’s FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004. References
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 1 more Show less
0.5.0
Fixed in
0.4.3
0.5.1
References
Updated Feb 03, 2026 · Source: OSV.dev |