PT-2026-4500 · Unknown+2 · Python Email Module+2

Bas Bloemsaat

+2

·

Published

2026-01-01

·

Updated

2026-05-05

·

CVE-2026-1299

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:C/A:N
Name of the Vulnerable Software and Affected Versions Python email module (affected versions not specified)
Description The BytesGenerator class within the email module did not correctly quote newlines for email headers during email message serialization. This flaw allows for header injection when an email is serialized, specifically when using "LiteralHeader" writing headers that do not adhere to email folding rules. The updated behavior rejects incorrectly folded headers in BytesGenerator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

ALSA-2026:2128
ALSA-2026:4165
ALSA-2026:4168
ALSA-2026:4216
ALSA-2026:4463
ALSA-2026:4473
ALSA-2026:4713
AZL-75219
AZL-75234
BDU:2026-05130
BIT-LIBPYTHON-2026-1299
BIT-PYTHON-2026-1299
BIT-PYTHON-MIN-2026-1299
CVE-2026-1299
ECHO-ADDC-A9AA-706B
OESA-2026-1356
OESA-2026-1461
OESA-2026-1463
OPENSUSE-SU-2026:10206-1
OPENSUSE-SU-2026:10222-1
OPENSUSE-SU-2026:10223-1
OPENSUSE-SU-2026:10398-1
OPENSUSE-SU-2026:10404-1
OPENSUSE-SU-2026:20254-1
OPENSUSE-SU-2026:20517-1
PSF-2026-8
RHSA-2026:2128
RHSA-2026:4165
RHSA-2026:4168
RHSA-2026:4216
RHSA-2026:4463
RHSA-2026:4473
RHSA-2026:4713
RHSA-2026:4746
RHSA-2026:5152
RHSA-2026:5215
RHSA-2026:5216
RHSA-2026:5218
RHSA-2026:5219
RHSA-2026:5221
RHSA-2026:5223
RHSA-2026:5225
RHSA-2026:5226
RHSA-2026:5315
RHSA-2026:5399
RHSA-2026:6008
RHSA-2026:6253
RHSA-2026:6464
RHSA-2026:7443
RHSA-2026:7661
RHSA-2026:8822
RHSA-2026:8824
SUSE-SU-2026:0642-1
SUSE-SU-2026:0873-1
SUSE-SU-2026:0884-1
SUSE-SU-2026:0891-1
SUSE-SU-2026:0897-1
SUSE-SU-2026:1062-1
SUSE-SU-2026:1090-1
SUSE-SU-2026:1107-1
SUSE-SU-2026:1117-1
SUSE-SU-2026:1349-1
SUSE-SU-2026:1354-1
SUSE-SU-2026:20543-1
SUSE-SU-2026:20581-1
SUSE-SU-2026:20951-1
SUSE-SU-2026:20956-1
SUSE-SU-2026:21104-1
SUSE-SU-2026:21178-1

Affected Products

Python Email Module
Red Os
Rocky Linux