CVE-2025-15366

Aliases:RHSA-2026:5979UBUNTU-CVE-2025-15366DEBIAN-CVE-2025-15366ALPINE-CVE-2025-15366CGA-22c2-ggw2-x8c7CGA-232h-86ff-rxm7CGA-26q2-45f4-w2r3CGA-28qc-w9ph-8hcpCGA-3wf5-mc2v-3252CGA-5jmx-v33j-c9v4CGA-fqhc-w2gg-fx34CGA-g97j-hvj9-46w3CGA-4x6g-cw77-rxqxCGA-h83p-r6v9-rp79CGA-rwm4-x7jf-4cgxCGA-rxwq-r3v4-5ccw
Deferred
Published: 20 Jan 2026, 21:40
Last modified:06 Aug 2026, 00:37

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v4.0 (cve.org)
EPSS Score
0.42% LOW
0% probability +0.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Jan 2026, 21:40
Published
Vulnerability first disclosed
06 Aug 2026, 00:37
Last Modified
Vulnerability information updated

Description

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

CVSS Metrics

  • v4.0MEDIUMScore: 5.9CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 5.9CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

EPSS Trends

Current EPSS score: 0.42% Percentile: 36%

Techniques & Countermeasures

  • CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')

    The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Affected Systems

  • alpinepython3

    < 3.14.7-r0

  • chainguardpython-3.10

    all

  • chainguardpython-3.11

    all

  • chainguardpython-3.12

    all

  • chainguardpython-3.13

    < 3.13.15-r0

  • chainguardpython-3.14

    < 3.14.7-r0

  • chainguardpython-3.9

    all

  • wolfipython-3.10

    all

  • wolfipython-3.11

    all

  • wolfipython-3.12

    all

  • wolfipython-3.13

    < 3.13.15-r0

  • wolfipython-3.14

    < 3.14.7-r0

  • debianjython

    all | all | all | all

  • debianpypy3

    all | all | all | all

  • debianpython2.7

    all

  • debianpython3.11

    all

  • debianpython3.13

    all | all

  • debianpython3.14

    all

  • debianpython3.9

    all

  • ubuntupython2.7

    all | all

  • ubuntupython3.10

    all

  • ubuntupython3.11

    all

  • ubuntupython3.12

    all

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.15.0 | < 3.15.0a6 | < 3.13.15 | ≥ 3.14.0, < 3.14.7 | ≥ 3.15.0a1, < 3.15.0a6

  • redhatpython3.13

    < 0:3.13.12-2.hum1

References (24)