Количество 82
Количество 82
GHSA-g82h-mgfp-jx8g
The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
BDU:2026-05131
Уязвимость модуля poplib интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2026:1062-1
Security update for python310
SUSE-SU-2026:1117-1
Security update for python311
SUSE-SU-2026:1107-1
Security update for python312
CVE-2026-1299
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
CVE-2026-1299
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
CVE-2026-1299
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
CVE-2026-1299
The email module, specifically the "BytesGenerator" class, didn\u2019 ...
SUSE-SU-2026:1349-1
Security update for python311
CVE-2026-0865
User-controlled header names and values containing newlines can allow injecting HTTP headers.
CVE-2026-0865
User-controlled header names and values containing newlines can allow injecting HTTP headers.
CVE-2026-0865
User-controlled header names and values containing newlines can allow injecting HTTP headers.
CVE-2026-0865
User-controlled header names and values containing newlines can allow ...
SUSE-SU-2026:1090-1
Security update for python3
SUSE-SU-2026:0897-1
Security update for python3
SUSE-SU-2026:0891-1
Security update for python
SUSE-SU-2026:0884-1
Security update for python36
SUSE-SU-2026:0873-1
Security update for python
GHSA-jh94-8q48-f3m3
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-g82h-mgfp-jx8g The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. | 0% Низкий | 6 месяцев назад | ||
BDU:2026-05131 Уязвимость модуля poplib интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольный код | CVSS3: 5.5 | 0% Низкий | 7 месяцев назад | |
SUSE-SU-2026:1062-1 Security update for python310 | 4 месяца назад | |||
SUSE-SU-2026:1117-1 Security update for python311 | 4 месяца назад | |||
SUSE-SU-2026:1107-1 Security update for python312 | 4 месяца назад | |||
CVE-2026-1299 The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator". | 1% Низкий | 6 месяцев назад | ||
CVE-2026-1299 The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator". | CVSS3: 7.1 | 1% Низкий | 6 месяцев назад | |
CVE-2026-1299 The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator". | 1% Низкий | 6 месяцев назад | ||
CVE-2026-1299 The email module, specifically the "BytesGenerator" class, didn\u2019 ... | 1% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:1349-1 Security update for python311 | 4 месяца назад | |||
CVE-2026-0865 User-controlled header names and values containing newlines can allow injecting HTTP headers. | 0% Низкий | 6 месяцев назад | ||
CVE-2026-0865 User-controlled header names and values containing newlines can allow injecting HTTP headers. | CVSS3: 4.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-0865 User-controlled header names and values containing newlines can allow injecting HTTP headers. | 0% Низкий | 6 месяцев назад | ||
CVE-2026-0865 User-controlled header names and values containing newlines can allow ... | 0% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:1090-1 Security update for python3 | 1% Низкий | 4 месяца назад | ||
SUSE-SU-2026:0897-1 Security update for python3 | 1% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:0891-1 Security update for python | 1% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:0884-1 Security update for python36 | 1% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:0873-1 Security update for python | 1% Низкий | 5 месяцев назад | ||
GHSA-jh94-8q48-f3m3 The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator". | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу