CVE-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Mar 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094 -

02 Mar 2026, 18:16

Type Values Removed Values Added
CWE CWE-93

02 Feb 2026, 23:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66 -

26 Jan 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6 -
  • () https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0 -
  • () https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796 -

20 Jan 2026, 23:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2 -

20 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 22:15

Updated : 2026-03-03 15:16


NVD link : CVE-2025-11468

Mitre link : CVE-2025-11468

CVE.ORG link : CVE-2025-11468


JSON object : View

Products Affected

No product.

CWE
CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')