Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-15367

25
FAUCET Score

CVE-2025-15367 describes a command injection vulnerability in the poplib module, where user-controlled input can lead to the injection of additional commands via newlines. While specific affected products are not listed, the vulnerability has a CVSS score of 5.9 (MEDIUM), indicating a network-based attack with low attack complexity, requiring high privileges to achieve high integrity impact. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB; however, it has garnered significant community discussion and media coverage, including security updates from SUSE.

Impacted Technologies

VendorProductVersion(s)CPE
Python Software FoundationCPython
>= 0, < 3.15.0a6CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

5.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
23.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 16th percentile among its peer group of 3,565 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-73.el8_10
View patch
ubuntupatch availablevia ubuntu_usn
Product: python3.5 (xenial)Fixed in: 3.5.2-2ubuntu0~16.04.13+esm22
ubuntupatch availablevia ubuntu_usn
Product: python3.6 (bionic)Fixed in: 3.6.9-1~18.04ubuntu1.13+esm9
ubuntupatch availablevia ubuntu_usn
Product: python3.7 (bionic)Fixed in: 3.7.5-2ubuntu1~18.04.2+esm10
ubuntupatch availablevia ubuntu_usn
Product: python3.8 (bionic)Fixed in: 3.8.0-3ubuntu1~18.04.2+esm10
ubuntupatch availablevia ubuntu_usn
Product: python3.8 (focal)Fixed in: 3.8.10-0ubuntu1~20.04.18+esm6
ubuntupatch availablevia ubuntu_usn
Product: python3.9 (focal)Fixed in: 3.9.5-3ubuntu0~20.04.1+esm10
ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.15
ubuntupatch availablevia ubuntu_usn
Product: python3.11 (jammy)Fixed in: 3.11.0~rc1-1~22.04.1~esm9
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.12
ubuntupatch availablevia ubuntu_usn
Product: python3.13 (questing)Fixed in: 3.13.7-1ubuntu0.4
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (questing)Fixed in: 3.14.0-1ubuntu0.3
ubuntupatch availablevia ubuntu_usn
Product: python3.4 (trusty)Fixed in: 3.4.3-1ubuntu1~14.04.7+esm20
ubuntupatch availablevia ubuntu_usn
Product: python3.5 (trusty)Fixed in: 3.5.2-2ubuntu0~16.04.4~14.04.1+esm10
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-azure-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-gcp-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.14
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python3
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.14
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-aws-cuda-rhel9
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-tech-preview/idea-rhel9

Vendor Advisories (2)

ubuntuUSN-8018-2

Python regression

Mar 9, 2026
redhatCVE-2025-15367Moderate

cpython: POP3 command injection in user-controlled commands

Jan 20, 2026

References

github.com / python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7
github.com / python/cpython/issues/143923
github.com / python/cpython/pull/143924
mail.python.org / archives/list/[email protected]/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE