« Volver al listado

CVE-2025-11468

Estado: AplazadaMedia (5.7)—

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-11468",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-11468",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-21T15:40:23.467208Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@python.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "PASSIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "HIGH",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@python.org",
      "affectedData": [
        {
          "repo": "https://github.com/python/cpython",
          "vendor": "Python Software Foundation",
          "modules": [
            "email"
          ],
          "product": "CPython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.10.20",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.15",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.13",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.13.0",
              "lessThan": "3.13.12",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.14.0",
              "lessThan": "3.14.3",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.15.0a1",
              "lessThan": "3.15.0a6",
              "versionType": "python"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-20T22:15:50.690",
  "references": [
    {
      "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/issues/143935",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/pull/143936",
      "source": "cna@python.org"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/",
      "source": "cna@python.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-93"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."
    },
    {
      "lang": "es",
      "value": "Al plegar un comentario largo en una cabecera de correo electrónico que contiene exclusivamente caracteres no plegables, el paréntesis no se conservaría. Esto podría usarse para inyectar cabeceras en mensajes de correo electrónico donde las direcciones son controladas por el usuario y no están saneadas."
    }
  ],
  "lastModified": "2026-06-17T08:30:31.043",
  "sourceIdentifier": "cna@python.org"
}