Bug 2431375 (CVE-2025-11468) - CVE-2025-11468 cpython: Missing character filtering in Python
Summary: CVE-2025-11468 cpython: Missing character filtering in Python
Keywords:
Status: NEW
Alias: CVE-2025-11468
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2431746 2431747 2431748 2431750 2431752 2431756 2431760 2431764 2431767 2431785 2431789 2431796 2431801 2431804 2431806 2431811 2431815 2431819 2431822 2431825 2431829 2431832 2431836
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-20 22:02 UTC by OSIDB Bzimport
Modified: 2026-01-21 20:34 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-20 22:02:46 UTC
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.


Note You need to log in before you can comment on or make changes to this bug.