Insecure Deserialization in extension "Mailqueue" (mailqueue)
Published Jan 20, 2026
5.2
MEDIUMCVSS 4.0
EPSS 0.14%
Description
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 .
Affected products
-
Affected
- ≥ 0, < 0.4.3
- ≥ 0.5.0, < 0.5.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| TYPO3 | Extension "Mailqueue" | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3591 Advisory
- https://github.com/CPS-IT/mailqueue/commit/12a0a35027bb5609917790a94e43bbf117abf733 patch
- https://github.com/CPS-IT/mailqueue/commit/fd09aa4e1a751551bae4b228bee814e22f2048db patch
- https://github.com/CPS-IT/mailqueue/security/advisories/GHSA-ggff-9mj3-7246
- https://github.com/advisories/GHSA-ggff-9mj3-7246 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-0895
- https://typo3.org/security/advisory/typo3-ext-sa-2026-001 vendor-advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub