CVE-2025-15366Patch

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-02-28); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-28: 2Mentions · 2026-04-15: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-28: 2Patch / Workaround · 2026-04-15: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-28: 202-2502-2804-15
Signal classification1 categories
Patch
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-02-282
Patch2
2026-04-151
Patch1
Full discourse4 posts
  • yuoka@yuoka_sfc
    Patch

    Debian LTS から regression, patches reverted っていうアナウンスが来てて、なんじゃろと思って見てたら、Ubuntu だと「Ignored, patch breaks RFC conformance」とか書いてあって面白い。無視される CVE… https://ubuntu.com/security/CVE-2025-15366

    Post summary

    The post notes that Debian LTS has reverted patches for a regression, while Ubuntu lists the CVE as ignored due to RFC conformity issues, linking to the Ubuntu security advisory.

    0000082
    266 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical patch for #Fedora 42's python3.9 is live. Fixes CVE-2026-1299 (email header injection) and CVE-2025-15366 (IMAP command injection). Read more: 👉 https://tinyurl.com/2yxa8r39 #Security https://t.co/uIPWcG9AAg

    Post summary

    Fedora 42’s python3.9 patch addresses CVE‑2026‑1299 and CVE‑2025‑15366, fixing email header and IMAP command injection vulnerabilities.

    00000222
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 ship security updates for python3.9, fixing critical command injection flaws (CVE-2026-1299, CVE-2026-0865, CVE-2025-15366, CVE-2025-15367). Developers should update. #Linux https://threatcluster.io/cluster/fedora-python-39-command-injection-vulnerabilities-addressed-ae49cdaf

    Post summary

    Fedora 42/43 include security updates that patch four critical command injection vulnerabilities in python3.9; developers are advised to apply the updates.

    00000146
    83 followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases security updates for Python 3.6 and 3.10 on SLES and openSUSE, patching HTTP header injection flaws CVE-2025-11468, CVE-2026-0672, CVE-2026-0865 and CVE-2025-15366. Users should update. https://threatcluster.io/cluster/multiple-cves-addressed-in-python-http-header-injection-vuln-4575b4d8

    Post summary

    SUSE has released security updates for Python 3.6 and 3.10 on SLES and openSUSE, addressing multiple HTTP header injection CVEs; users are advised to apply the patches.

    0000040
    79 followersView on X

Explore more