CVE-2025-15366
Published: January 22, 2026Last modified: January 28, 2026
Description
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | python3 | Fixed (3.11.13-r3) |
| 25 LTS | python3 | Fixed (3.12.12-r2) | |
| Stream | python3 | Fixed (3.12.12-r3) | |
| Hardened Containers | 23 LTS | python3 | Fixed (3.11.13-r3) |
| 25 LTS | python3 | Fixed (3.12.12-r2) | |
| Stream | python3 | Fixed (3.12.12-r3) |
References
- https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1
- https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45
- https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2
- https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d
- https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a
- https://github.com/python/cpython/issues/143921
- https://github.com/python/cpython/pull/143922
- https://mail.python.org/archives/list/[email protected]/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/