GHSA-9j88-vvj5-vhgr: STARTTLS Response Injection and SASL Downgrade in MailKit Vulnerability ID: GHSA-9J88-VVJ5-VHGR CVSS Score: 6.5 Published: 2026-04-18 MailKit versions prior to 4.16.0 contain a STARTTLS response injection vulnerability. A network-positioned attacker can inject plaintext protocol responses into the client's internal read buffer before the TLS handshake completes, causing th