CVE Vulnerabilities

CVE-2026-1299

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Jan 23, 2026 | Modified: Feb 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The email module, specifically the BytesGenerator class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using LiteralHeader writing headers that dont respect email folding rules, the new behavior will reject the incorrectly folded headers in BytesGenerator.

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-73.el8_10*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-73.el8_10*
Python3.13Ubuntudevel*
Python3.14Ubuntudevel*

Potential Mitigations

References