Home

Description

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

PUBLISHED Reserved 2025-12-30 | Published 2026-01-20 | Updated 2026-02-11 | Assigner PSF




MEDIUM: 5.9CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Product status

Default status
unaffected

Any version before 3.15.0a6
affected

Credits

Omar M. Hasan reporter

References

github.com/python/cpython/issues/143921 issue-tracking

github.com/python/cpython/pull/143922 patch

mail.python.org/.../thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/ vendor-advisory

github.com/...ommit/6262704b134db2a4ba12e85ecfbd968534f28b45 patch

cve.org (CVE-2025-15366)

nvd.nist.gov (CVE-2025-15366)

Download JSON