CVE-2026-1299 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for hea…
Medium CVSS: 6.0

CVE-2026-1299

The
email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
Vendor
-
Product
-
CWE
CWE-93
Yayın Tarihi
2026-01-23 17:16:12
Güncelleme
2026-02-13 17:16:12
Source Identifier
cna@python.org
KEV Date Added
-

Kategoriler

Referanslar