TYPO3 Mailqueue Extension Insecure Deserialization Vulnerability

Vulnerability

A vulnerability allowing insecure deserialization has been identified in the TYPO3 Mailqueue extension, specifically in versions 0.5.0, 0.4.2 and below. This issue arises because the extension overrides a fix for deserialization vulnerabilities in the TYPO3 core, leaving users with patched core versions still exposed. The vulnerability is rooted in the extension's handling of TYPO3's FileSpool component, which was previously vulnerable to similar deserialization issues.

Impact

Exploitation of this vulnerability allows for insecure deserialization, which can lead to various attacks such as remote code execution or data manipulation, depending on the context in which the deserialized data is used.

Remediation

Users are advised to update to TYPO3 Mailqueue extension versions 0.5.1 or 0.4.3, available through the TYPO3 extension manager, Packagist, or directly from the TYPO3 Extensions Repository.

Added: Jan 20, 2026, 8:21 AM
Updated: Jan 20, 2026, 1:43 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.