Back

MEDIUM

IMAP command injection in user-controlled commands

Published Jan 20, 2026

Description

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

Affected products

Remediation

Red Hat statement

To exploit this issue, an attacker needs to have the privileges required to send malicious input to an application that sends IMAP commands to a server. Additionally, this flaw can allow attackers to manipulate the state of the mailbox (e.g., delete emails, move folders, flag messages) and to potentially read metadata or specific email content, but it does not allow arbitrary code execution or OS command injection. Due to these reasons, this issue has been rated with a moderate severity.

Red Hat mitigation

To mitigate this vulnerability, ensure that no data passed to the imaplib module contains newline or carriage return characters.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PSF
Published Jan 20, 2026
Updated Aug 6, 2026
Reserved Dec 30, 2025
CISA Vulnrichment
Updated Jan 22, 2026
NVD
Status Deferred
Modified Aug 6, 2026
Red Hat
Severity Moderate
Public date Jan 20, 2026