CVE-2025-15367: Python Software Foundation Cpython

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

Affected products

Published 2026-01-20. Last modified 2026-06-17.