CVE-2025-11468 describes a vulnerability where improperly handled email header folding, specifically with long comments containing unfoldable characters, could lead to header injection. This flaw affects email systems where user-controlled addresses are not adequately sanitized, though specific affected products are not detailed. The vulnerability is rated Medium severity (CVSS 5.7), indicating a low attack complexity and potential for high integrity impact, allowing attackers to inject arbitrary headers. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, suggesting a recognized risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.10.20CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.15CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.12.0, < 3.12.13CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.13.0, < 3.13.12CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, < 3.14.3CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.