Home

Description

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

PUBLISHED Reserved 2025-12-30 | Published 2026-01-20 | Updated 2026-02-11 | Assigner PSF




MEDIUM: 5.9CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Product status

Default status
unaffected

Any version before 3.15.0a6
affected

Credits

Omar M. Hasan reporter

References

github.com/python/cpython/pull/143924 patch

github.com/python/cpython/issues/143923 issue-tracking

mail.python.org/.../thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/ vendor-advisory

github.com/...ommit/b234a2b67539f787e191d2ef19a7cbdce32874e7 patch

cve.org (CVE-2025-15367)

nvd.nist.gov (CVE-2025-15367)

Download JSON