Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-11468

Опубликовано: 20 янв. 2026
Источник: debian

Описание

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.3-1package
python3.13fixed3.13.12-1package
python3.13fixed3.13.5-2+deb13u1trixiepackage
python3.11removedpackage
python3.11fixed3.11.2-6+deb12u7bookwormpackage
python3.9removedpackage
python2.7not-affectedpackage
pypy3fixed7.3.21+dfsg-1package
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3postponedbullseyepackage
jythonnot-affectedpackage

Примечания

  • https://github.com/python/cpython/issues/143935

  • https://github.com/python/cpython/pull/143936

  • Fixed by: https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2 (main)

  • Fixed by: https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6 (3.14 branch)

  • Fixed by: https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796 (3.13 branch)

  • Fixed by: https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0 (3.11 branch)

Связанные уязвимости

ubuntu
6 месяцев назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

CVSS3: 4.5
redhat
6 месяцев назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

nvd
6 месяцев назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

github
6 месяцев назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность данных