CVE-2025-11468: Python Software Foundation Cpython

Medium severity, CVSS 5.7. EPSS: 0.6% chance of exploitation in the next 30 days.

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

Affected products

  • Python Software Foundation Cpython: before 3.10.20 (fixed in 3.10.20); from 3.11.0, before 3.11.15 (fixed in 3.11.15); from 3.12.0, before 3.12.13 (fixed in 3.12.13); from 3.13.0, before 3.13.12 (fixed in 3.13.12); from 3.14.0, before 3.14.3 (fixed in 3.14.3); from 3.15.0a1, before 3.15.0a6 (fixed in 3.15.0a6)

Published 2026-01-20. Last modified 2026-06-17.