CVE-2025-15366: Python Software Foundation Cpython
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Affected products
- Python Software Foundation Cpython: before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); from 3.15.0a1, before 3.15.0a6 (fixed in 3.15.0a6)
Published 2026-01-20. Last modified 2026-08-06.