HackTesting
HomeArticlesTagsContact

CVE-2025-15366

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

Credits

Omar M. Hasan

References

https://github.com/python/cpython/issues/143921
https://github.com/python/cpython/pull/143922
https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/
https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45
https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d
https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a
https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1
https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2
Published
Jan 20, 2026 21:40:24 UTC
Updated
Aug 5, 2026 13:29:42 UTC
Reserved
Dec 30, 2025 16:06:41 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2026 HackTesting. All rights reserved.