CVE-2024-6923: Python Cpython

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

Affected products

  • Python Cpython: up to and including 3.13.0rc2
  • Python Software Foundation Cpython: before 3.8.20 (fixed in 3.8.20); from 3.9.0, before 3.9.20 (fixed in 3.9.20); from 3.10.0, before 3.10.15 (fixed in 3.10.15); from 3.11.0, before 3.11.10 (fixed in 3.11.10); from 3.12.0, before 3.12.5 (fixed in 3.12.5); from 3.13.0a1, before 3.13.0rc2 (fixed in 3.13.0rc2)

Published 2024-08-01. Last modified 2026-06-17.