PT-2025-9128 · Python+6 · Python+6

Seth Larson

·

Published

2025-02-28

·

Updated

2025-11-12

·

CVE-2025-1795

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Python versions prior to 3.13.2 Python versions prior to 3.12.9 Python versions prior to 3.11.12 python3.9 (affected versions not specified)
Description The issue relates to incorrect handling of commas during address list folding and Unicode encoding of email headers. Specifically, when a separating comma appears on a folded line and is Unicode-encoded, the separator itself is also encoded, potentially leading to misinterpretation of the email header by some mail servers. This could allow for an attacker to perform a header injection attack.
Recommendations Update to Python version 3.13.2 or later. Update to Python version 3.12.9 or later. Update to Python version 3.11.12 or later. For python3.9, update to a newer version that contains a fix for this vulnerability.

Fix

Improper Encoding or Escaping of Output

RCE

Weakness Enumeration

Related Identifiers

AZL-57675
BDU:2025-11593
BIT-LIBPYTHON-2025-1795
BIT-PYTHON-2025-1795
BIT-PYTHON-MIN-2025-1795
CVE-2025-1795
DLA-4087-1
DLA-4354-1
ECHO-27F5-2176-4ABE
MGASA-2025-0280
OESA-2025-2290
OESA-2025-2302
OESA-2025-2303
OESA-2025-2304
OESA-2025-2305
OESA-2025-2306
OPENSUSE-SU-2025:14872-1
OPENSUSE-SU-2025:14873-1
OPENSUSE-SU-2025:14885-1
OPENSUSE-SU-2025_0883-1
OPENSUSE-SU-2025_0981-1
OPENSUSE-SU-2025_0982-1
PSF-2025-3
SUSE-SU-2025:02074-1
SUSE-SU-2025:0883-1
SUSE-SU-2025:0981-1
SUSE-SU-2025:0982-1
SUSE-SU-2025:20154-1
SUSE-SU-2025:20374-1
SUSE-SU-2025_0981-1
SUSE-SU-2025_0982-1
USN-7570-1

Affected Products

Astra Linux
Debian
Linuxmint
Python
Red Os
Suse
Ubuntu