IMAP command injection in user-controlled commands
Published Jan 20, 2026
5.9
MEDIUMCVSS 4.0
EPSS 0.42%
Description
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Affected products
-
- Version 0StatusaffectedConstraints<3.13.15
- Version 3.14.0StatusaffectedConstraints<3.14.7
- Version 3.15.0a1StatusaffectedConstraints<3.15.0a6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Python Software Foundation | CPython | unaffected |
|
No data.
No data.
Red Hat AI Inference Server 3.3
rhaiis/model-opt-cuda-rhel9:1775749857
Fixed · RHSA-2026:8748
Red Hat AI Inference Server 3.3
rhaiis/vllm-cuda-rhel9:1775680192
Fixed · RHSA-2026:8746
Red Hat AI Inference Server 3.3
rhaiis/vllm-rocm-rhel9:1775680262
Fixed · RHSA-2026:8747
Red Hat AI Inference Server 3.3
rhaiis/vllm-spyre-rhel9:1778244546
Fixed · RHSA-2026:16174
Red Hat Ceph Storage 8
rhceph/rhceph-8-rhel9:1774002867
Fixed · RHSA-2026:5606
Red Hat Discovery 2
discovery/discovery-server-rhel9:1775668717
Fixed · RHSA-2026:7329
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1775675922
Fixed · RHSA-2026:7329
Red Hat Enterprise Linux 10
python3.12-0:3.12.12-3.el10_1.1
Fixed · RHSA-2026:4713
Red Hat Enterprise Linux 10.0 Extended Update Support
python3.12-0:3.12.9-2.el10_0.7
Fixed · RHSA-2026:5315
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
python-0:2.6.6-70.el6_10.2
Fixed · RHSA-2026:6007
Red Hat Enterprise Linux 7 Extended Lifecycle Support
python-0:2.7.5-94.el7_9.3
Fixed · RHSA-2026:5393
Red Hat Enterprise Linux 7 Extended Lifecycle Support
python3-0:3.6.8-21.el7_9.4
Fixed · RHSA-2026:6464
Red Hat Enterprise Linux 8
python3-0:3.6.8-73.el8_10
Fixed · RHSA-2026:2128
Red Hat Enterprise Linux 8
python3-0:3.6.8-73.el8_10
Fixed · RHSA-2026:2128
Red Hat Enterprise Linux 8
python3.11-0:3.11.13-5.el8_10
Fixed · RHSA-2026:4473
Red Hat Enterprise Linux 8
python3.12-0:3.12.12-3.el8_10
Fixed · RHSA-2026:4463
Red Hat Enterprise Linux 8.2 Advanced Update Support
python3-0:3.6.8-24.el8_2.6
Fixed · RHSA-2026:5216
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
python3-0:3.6.8-39.el8_4.9
Fixed · RHSA-2026:5221
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
python3-0:3.6.8-39.el8_4.9
Fixed · RHSA-2026:5221
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
python3-0:3.6.8-47.el8_6.11
Fixed · RHSA-2026:5215
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
python3-0:3.6.8-47.el8_6.11
Fixed · RHSA-2026:5215
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
python3-0:3.6.8-47.el8_6.11
Fixed · RHSA-2026:5215
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
python3-0:3.6.8-51.el8_8.13
Fixed · RHSA-2026:6008
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
python3.11-0:3.11.2-2.el8_8.8
Fixed · RHSA-2026:5152
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
python3-0:3.6.8-51.el8_8.13
Fixed · RHSA-2026:6008
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
python3.11-0:3.11.2-2.el8_8.8
Fixed · RHSA-2026:5152
Red Hat Enterprise Linux 9
python3.11-0:3.11.13-5.1.el9_7
Fixed · RHSA-2026:4216
Red Hat Enterprise Linux 9
python3.12-0:3.12.12-4.el9_7.1
Fixed · RHSA-2026:4165
Red Hat Enterprise Linux 9
python3.9-0:3.9.25-3.el9_7.1
Fixed · RHSA-2026:4168
Red Hat Enterprise Linux 9
python3.9-0:3.9.25-3.el9_7.1
Fixed · RHSA-2026:4168
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
python3.9-0:3.9.10-4.el9_0.9
Fixed · RHSA-2026:5219
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
python3.11-0:3.11.2-2.el9_2.10
Fixed · RHSA-2026:5223
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
python3.9-0:3.9.16-1.el9_2.12
Fixed · RHSA-2026:5225
Red Hat Enterprise Linux 9.4 Extended Update Support
python3.11-0:3.11.7-1.el9_4.11
Fixed · RHSA-2026:6253
Red Hat Enterprise Linux 9.4 Extended Update Support
python3.12-0:3.12.1-4.el9_4.11
Fixed · RHSA-2026:5399
Red Hat Enterprise Linux 9.4 Extended Update Support
python3.9-0:3.9.18-3.el9_4.11
Fixed · RHSA-2026:5226
Red Hat Enterprise Linux 9.6 Extended Update Support
python3.12-0:3.12.9-1.el9_6.6
Fixed · RHSA-2026:4746
Red Hat Enterprise Linux 9.6 Extended Update Support
python3.9-0:3.9.21-2.el9_6.4
Fixed · RHSA-2026:5218
Red Hat Hardened Images
python3-11-main-3.11.15-4.hum1
Fixed · RHSA-2026:8822
Red Hat Hardened Images
python3-12-main-3.12.13-3.hum1
Fixed · RHSA-2026:8824
Red Hat Hardened Images
python3-13-main-3.13.12-2.hum1
Fixed · RHSA-2026:5979
Red Hat Hardened Images
python3-14-main-3.14.4-2.hum1
Fixed · RHSA-2026:9228
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1773670073
Fixed · RHSA-2026:4943
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1773672059
Fixed · RHSA-2026:4943
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1773668803
Fixed · RHSA-2026:4943
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1773670137
Fixed · RHSA-2026:4943
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
python3.14
Affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux 8
python39-devel:3.9/python39
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
python3.14
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Will not fix
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces-tech-preview/idea-rhel9
Will not fix
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server 3.3 | rhaiis/model-opt-cuda-rhel9:1775749857 | Fixed | RHSA-2026:8748 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-cuda-rhel9:1775680192 | Fixed | RHSA-2026:8746 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-rocm-rhel9:1775680262 | Fixed | RHSA-2026:8747 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-spyre-rhel9:1778244546 | Fixed | RHSA-2026:16174 |
| Red Hat Ceph Storage 8 | rhceph/rhceph-8-rhel9:1774002867 | Fixed | RHSA-2026:5606 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1775668717 | Fixed | RHSA-2026:7329 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1775675922 | Fixed | RHSA-2026:7329 |
| Red Hat Enterprise Linux 10 | python3.12-0:3.12.12-3.el10_1.1 | Fixed | RHSA-2026:4713 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | python3.12-0:3.12.9-2.el10_0.7 | Fixed | RHSA-2026:5315 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | python-0:2.6.6-70.el6_10.2 | Fixed | RHSA-2026:6007 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | python-0:2.7.5-94.el7_9.3 | Fixed | RHSA-2026:5393 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | python3-0:3.6.8-21.el7_9.4 | Fixed | RHSA-2026:6464 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-73.el8_10 | Fixed | RHSA-2026:2128 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-73.el8_10 | Fixed | RHSA-2026:2128 |
| Red Hat Enterprise Linux 8 | python3.11-0:3.11.13-5.el8_10 | Fixed | RHSA-2026:4473 |
| Red Hat Enterprise Linux 8 | python3.12-0:3.12.12-3.el8_10 | Fixed | RHSA-2026:4463 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | python3-0:3.6.8-24.el8_2.6 | Fixed | RHSA-2026:5216 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | python3-0:3.6.8-39.el8_4.9 | Fixed | RHSA-2026:5221 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | python3-0:3.6.8-39.el8_4.9 | Fixed | RHSA-2026:5221 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | python3-0:3.6.8-47.el8_6.11 | Fixed | RHSA-2026:5215 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | python3-0:3.6.8-47.el8_6.11 | Fixed | RHSA-2026:5215 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | python3-0:3.6.8-47.el8_6.11 | Fixed | RHSA-2026:5215 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | python3-0:3.6.8-51.el8_8.13 | Fixed | RHSA-2026:6008 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | python3.11-0:3.11.2-2.el8_8.8 | Fixed | RHSA-2026:5152 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | python3-0:3.6.8-51.el8_8.13 | Fixed | RHSA-2026:6008 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | python3.11-0:3.11.2-2.el8_8.8 | Fixed | RHSA-2026:5152 |
| Red Hat Enterprise Linux 9 | python3.11-0:3.11.13-5.1.el9_7 | Fixed | RHSA-2026:4216 |
| Red Hat Enterprise Linux 9 | python3.12-0:3.12.12-4.el9_7.1 | Fixed | RHSA-2026:4165 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.25-3.el9_7.1 | Fixed | RHSA-2026:4168 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.25-3.el9_7.1 | Fixed | RHSA-2026:4168 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | python3.9-0:3.9.10-4.el9_0.9 | Fixed | RHSA-2026:5219 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | python3.11-0:3.11.2-2.el9_2.10 | Fixed | RHSA-2026:5223 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | python3.9-0:3.9.16-1.el9_2.12 | Fixed | RHSA-2026:5225 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | python3.11-0:3.11.7-1.el9_4.11 | Fixed | RHSA-2026:6253 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | python3.12-0:3.12.1-4.el9_4.11 | Fixed | RHSA-2026:5399 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | python3.9-0:3.9.18-3.el9_4.11 | Fixed | RHSA-2026:5226 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | python3.12-0:3.12.9-1.el9_6.6 | Fixed | RHSA-2026:4746 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | python3.9-0:3.9.21-2.el9_6.4 | Fixed | RHSA-2026:5218 |
| Red Hat Hardened Images | python3-11-main-3.11.15-4.hum1 | Fixed | RHSA-2026:8822 |
| Red Hat Hardened Images | python3-12-main-3.12.13-3.hum1 | Fixed | RHSA-2026:8824 |
| Red Hat Hardened Images | python3-13-main-3.13.12-2.hum1 | Fixed | RHSA-2026:5979 |
| Red Hat Hardened Images | python3-14-main-3.14.4-2.hum1 | Fixed | RHSA-2026:9228 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1773670073 | Fixed | RHSA-2026:4943 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1773672059 | Fixed | RHSA-2026:4943 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1773668803 | Fixed | RHSA-2026:4943 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1773670137 | Fixed | RHSA-2026:4943 |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | python3.14 | Affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39-devel:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.14 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Will not fix | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces-tech-preview/idea-rhel9 | Will not fix | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this issue, an attacker needs to have the privileges required to send malicious input to an application that sends IMAP commands to a server. Additionally, this flaw can allow attackers to manipulate the state of the mailbox (e.g., delete emails, move folders, flag messages) and to potentially read metadata or specific email content, but it does not allow arbitrary code execution or OS command injection. Due to these reasons, this issue has been rated with a moderate severity.
Red Hat mitigation
To mitigate this vulnerability, ensure that no data passed to the imaplib module contains newline or carriage return characters.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jan 22, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.42% (0.00422) | 34.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.32% (0.00315) | 22.95th | v5 (v2026.06.15) |
| Jan 21, 2026 | 0.04% (0.00043) | 13.16th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2025-15366 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2431368 Issue Tracking
- https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1 patch
- https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45 patch
- https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2 patch
- https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d patch
- https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a patch
- https://github.com/python/cpython/issues/143921 issue-tracking
- https://github.com/python/cpython/pull/143922 patch
- https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-15366
- https://www.cve.org/CVERecord?id=CVE-2025-15366
Change history (0)
No recorded changes yet.