CVE-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Al plegar un comentario largo en una cabecera de correo electrónico que contiene exclusivamente caracteres no plegables, el paréntesis no se conservaría. Esto podría usarse para inyectar cabeceras en mensajes de correo electrónico donde las direcciones son controladas por el usuario y no están saneadas.

03 Mar 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094 -

02 Mar 2026, 18:16

Type Values Removed Values Added
CWE CWE-93

02 Feb 2026, 23:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66 -

26 Jan 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6 -
  • () https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0 -
  • () https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796 -

20 Jan 2026, 23:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2 -

20 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 22:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-11468

Mitre link : CVE-2025-11468

CVE.ORG link : CVE-2025-11468


JSON object : View

Products Affected

No product.

CWE
CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')