PT-2025-9128 · Python+6 · Python+6
Seth Larson
·
Published
2025-02-28
·
Updated
2025-11-12
·
CVE-2025-1795
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 3.13.2
Python versions prior to 3.12.9
Python versions prior to 3.11.12
python3.9 (affected versions not specified)
Description
The issue relates to incorrect handling of commas during address list folding and Unicode encoding of email headers. Specifically, when a separating comma appears on a folded line and is Unicode-encoded, the separator itself is also encoded, potentially leading to misinterpretation of the email header by some mail servers. This could allow for an attacker to perform a header injection attack.
Recommendations
Update to Python version 3.13.2 or later.
Update to Python version 3.12.9 or later.
Update to Python version 3.11.12 or later.
For python3.9, update to a newer version that contains a fix for this vulnerability.
Fix
Improper Encoding or Escaping of Output
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Python
Red Os
Suse
Ubuntu