Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-20107

28
FAUCET Score

CVE-2015-20107 describes a shell command injection vulnerability in the mailcap module of Python (CPython) versions up to 3.10.8, also affecting Fedora Project and NetApp products. Attackers can inject commands into applications using mailcap.findmatch with untrusted input due to a lack of proper escaping. This vulnerability has a CVSS score of 7.6 (High), indicating it can be exploited remotely with low complexity and user interaction, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, nor are there public Metasploit or ExploitDB modules, though it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.7.0, <= 3.7.15CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.8.0, <= 3.8.15CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.9.0, <= 3.9.15CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.10.0, < 3.10.8CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.16%
Probability of exploitation in next 30 days
EPSS Percentile
93.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0716 is in the 93rd percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

elasticpatch availablevia llm_extracted
Fixed in: ['8.1.13', '8.2.10', '9.0.4', '9.0.2209.3']
microsoftpatch availablevia msrc
Product: 16822-16820Fixed in: 2.7.18-11
microsoftpatch availablevia msrc
Product: 16824-16823Fixed in: 3.9.13-5
microsoftpatch availablevia msrc
Product: 16821-16820Fixed in: 3.7.13-4
microsoftpatch availablevia msrc
Product: cm1 python3 3.7.13-4 on CBL Mariner 1.0Fixed in: 3.7.13-4
microsoftpatch availablevia msrc
Product: cm1 python2 2.7.18-11 on CBL Mariner 1.0Fixed in: 2.7.18-11
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.13-5 on CBL Mariner 2.0Fixed in: 3.9.13-5
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9-0:3.9.14-1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-0:3.8.14-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38:3.8-8070020220916150349.bd194b04
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8070020220916150556.be1f0497
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-47.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7-8070020220617114255.056aacbc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38-devel:3.8-8070020220916150349.bd194b04
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8070020220916150556.be1f0497
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: python27

Vendor Advisories (5)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
elasticllm-elastic-1862d04bb8fb6af4HIGH

February Third Party Package Updates in Splunk Enterprise

Feb 14, 2023
microsoft2022-Apr/CVE-2015-20107Important

In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9

Apr 12, 2022
redhatCVE-2015-20107Moderate

python: mailcap: findmatch() function does not sanitize the second argument

Aug 2, 2015

References

lists.debian.org / debian-lts-announce/2024/12/msg00000.html
bugs.python.org / issue24778
ExploitIssue TrackingVendor Advisory
github.com / python/cpython/issues/68966
Issue TrackingThird Party Advisory
lists.debian.org / debian-lts-announce/2023/05/msg00024.html
lists.debian.org / debian-lts-announce/2023/06/msg00039.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/46KWPTI72SSEOF53DOYQBQOCN4QQB2GE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/53TQZFLS6O3FLIMVSXFEEPZSWLDZLBOX
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/57NECACX333A3BBZM2TR2VZ4ZE3UG3SN
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/5DBVY4YC2P6EPZZ2DROOXHDOWZ4BJFLW
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6QIKVSW3H6W2GQGDE5DTIWLGFNH6KKEW
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AKGMYDVKI3XNM27B6I6RQ6QV3TVJAUCG
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ERYMM2QVDPOJLX4LYXWYIQN5FOIJLDRY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/F3LNY2NHM6J22O6Q5ANOE3SZRK3OACKR
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FCIO2W4DUVVMI6L52QCC4TT2B3K5VWHS
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FIRUTX47BJD2HYJDLMI7JJBVCYFAPKAQ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GPCLGZZJPVXFWUWVV5WCD5FNUAFLKBDN
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HAI2GBC7WKH7J5NH6J2IW5RT3VF2SF5M
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KAY6VBNVEFUXKJF37WFHYXUSRDEK34N3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MYG3EMFR7ZHC46TDNM7SNWO64A3W7EUF
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ONXSGLASNLGFL57YU6WT6Y5YURSFV43U
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PTTZGLD2YBMMG6U6F5HOTPOGGPBIURMA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/W5664BGZVTA46LQDNTYX5THG6CN4FYJX
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XO2H6CKWLRGTTZCGUQVELW6LUH437Q3O
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD
python-security.readthedocs.io / vuln/mailcap-shell-injection.html
PatchThird Party Advisory
security.gentoo.org / glsa/202305-02
security.netapp.com / advisory/ntap-20220616-0001
Third Party Advisory