CVE-2025-11468
Folding email comments of unfoldable characters doesn't preserve parenthesis
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
Denis Ledoux discovered that Python incorrectly parsed email message headers. An attacker could possibly use this issue to inject arbitrary headers into email messages. This issue only affected python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python inefficiently parsed XML input with quadratic complexity. An attacker could possibly use this issue to cause a denial of service.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-10-07 CVE Reserved
- 2026-01-20 CVE Published
- 2026-03-03 CVE Updated
- 2026-03-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
CAPEC
References (9)
| URL | Tag | Source |
|---|---|---|
| https://github.com/python/cpython/issues/143935 | Issue Tracking |
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | < 3.10.20 Search vendor "Python Software Foundation" for product "CPython" and version " < 3.10.20" | en |
Affected
| ||||||
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | >= 3.11.0 < 3.11.15 Search vendor "Python Software Foundation" for product "CPython" and version " >= 3.11.0 < 3.11.15" | en |
Affected
| ||||||
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | >= 3.12.0 < 3.12.13 Search vendor "Python Software Foundation" for product "CPython" and version " >= 3.12.0 < 3.12.13" | en |
Affected
| ||||||
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | >= 3.13.0 < 3.13.12 Search vendor "Python Software Foundation" for product "CPython" and version " >= 3.13.0 < 3.13.12" | en |
Affected
| ||||||
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | >= 3.14.0 < 3.14.3 Search vendor "Python Software Foundation" for product "CPython" and version " >= 3.14.0 < 3.14.3" | en |
Affected
| ||||||
