CVE-2025-11468Patch

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-25); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-25: 1Mentions · 2026-03-07: 1Mentions · 2026-03-19: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-02-25: 102-2503-0703-19
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-03-071
General1
2026-03-191
Patch1
Full discourse3 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-11468 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/441 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda has updated its base images, removing CVE‑2025‑11468, indicating the vulnerability has been patched.

    0000097
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2025-11468 impacts python in 7 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/441 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A medium‑severity CVE (CVE-2025-11468) has been detected in AWS Lambda Python base images; references to issue discussions and a website are provided, but no technical, exploit, or patch details are offered.

    00000158
    31 followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases security updates for Python 3.6 and 3.10 on SLES and openSUSE, patching HTTP header injection flaws CVE-2025-11468, CVE-2026-0672, CVE-2026-0865 and CVE-2025-15366. Users should update. https://threatcluster.io/cluster/multiple-cves-addressed-in-python-http-header-injection-vuln-4575b4d8

    Post summary

    SUSE has released security updates for Python 3.6 and 3.10 on SLES and openSUSE, addressing multiple HTTP header injection CVEs; users are advised to apply the patches.

    0000040
    79 followersView on X

Explore more