FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Python -- imaplib module, when passed a user-controlled command, can have additional commands injected using newlines

Affected packages
0 <= python310
0 <= python311
0 <= python312
python313 < 3.13.15
python313t < 3.13.15
python314 < 3.14.7
python314t < 3.14.7
python315 < 3.15.0.b4

Details

VuXML ID 0be929a5-2e0f-11f1-88c7-00a098b42aeb
Discovery 2026-01-20
Entry 2026-04-01
Modified 2026-08-08

Python Software Foundation Security Developer reports:

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing specific control characters.

References

CVE Name CVE-2025-15366
URL https://cveawg.mitre.org/api/cve/CVE-2025-15366