Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-11468

Опубликовано: 20 янв. 2026
Источник: debian
EPSS Низкий

Описание

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.3-1package
python3.13fixed3.13.12-1package
python3.11removedpackage
python3.9removedpackage
python2.7not-affectedpackage
pypy3unfixedpackage
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3postponedbullseyepackage
jythonnot-affectedpackage

Примечания

  • https://github.com/python/cpython/issues/143935

  • https://github.com/python/cpython/pull/143936

  • Fixed by: https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2 (main)

  • Fixed by: https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6 (3.14 branch)

  • Fixed by: https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796 (3.13 branch)

  • Fixed by: https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0 (3.11 branch)

EPSS

Процентиль: 18%
0.00058
Низкий

Связанные уязвимости

ubuntu
18 дней назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

nvd
18 дней назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

github
18 дней назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

EPSS

Процентиль: 18%
0.00058
Низкий