CVE 5.2 MEDIUM

Insecure Deserialization in extension “Mailqueue” (mailqueue)_CVE-2026-0895

5.2 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H

Description

The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related TYPO3 Core Security Advisory TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 .

Basic Information

ID CVE-2026-0895
Source TYPO3
Published Jan 20, 2026 at 07:19
Modified Jan 20, 2026 at 07:21

Affected Product

Vendor TYPO3
Product Extension "Mailqueue"
Affected Versions TYPO3 Extension "Mailqueue" 0
TYPO3 Extension "Mailqueue" 0.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.