Insecure Deserialization Vulnerability in TYPO3 FileSpool Extension by TYPO3
CVE-2026-0895
What is CVE-2026-0895?
The TYPO3 FileSpool extension is vulnerable to Insecure Deserialization, stemming from its reliance on outdated code from the TYPO3 core. Even if the TYPO3 core has been patched, using this extension can still expose systems to potential attacks due to the inherited flaw. This vulnerability allows malicious actors to manipulate serialized objects, leading to unauthorized actions or data leaks. It is essential for users of this extension to review their implementation and consider applying the necessary patches to mitigate risks. For detailed information, refer to the TYPO3 Core Security Advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Extension "Mailqueue" 0 < 0.4.3
Extension "Mailqueue" 0.5.0 < 0.5.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
