Bug 2431368 (CVE-2025-15366) - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
Summary: CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
Keywords:
Status: NEW
Alias: CVE-2025-15366
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2431610 2431611 2431612 2431613 2431614 2431615 2431616 2431617 2431618 2431619 2431620 2431621 2431622 2431623 2431624 2431625 2431626 2431627 2431628 2431629 2431630 2431631 2431632
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-20 22:01 UTC by OSIDB Bzimport
Modified: 2026-01-21 14:51 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-20 22:01:58 UTC
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.


Note You need to log in before you can comment on or make changes to this bug.