FlawAtlas
Search the atlas
CVE-2025-11468 Moderate

CVE-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

Exploit probability 0.5%
Published January 20, 2026
Required by Not available
Last source change March 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

212 explicit affected versions

Bitnami python-min
Bitnami python
Bitnami libpython
Unknown Unknown

400 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-python-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

View original source
Open Source Vulnerabilities BIT-python-min-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

View original source
Open Source Vulnerabilities BIT-libpython-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

View original source
Open Source Vulnerabilities PSF-2026-1

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

View original source
Open Source Vulnerabilities CVE-2025-11468

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

View original source

05 / REFERENCES

Further evidence