CVE Vulnerabilities

CVE-2026-1299

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Jan 23, 2026 | Modified: Apr 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The email module, specifically the BytesGenerator class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using LiteralHeader writing headers that dont respect email folding rules, the new behavior will reject the incorrectly folded headers in BytesGenerator.

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatpython3.12-0:3.12.12-3.el10_1.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatpython3.12-0:3.12.9-2.el10_0.7*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatpython3-0:3.6.8-21.el7_9.4*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-73.el8_10*
Red Hat Enterprise Linux 8RedHatpython3.12-0:3.12.12-3.el8_10*
Red Hat Enterprise Linux 8RedHatpython3.11-0:3.11.13-5.el8_10*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-73.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatpython3-0:3.6.8-24.el8_2.6*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatpython3-0:3.6.8-39.el8_4.9*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatpython3-0:3.6.8-39.el8_4.9*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatpython3-0:3.6.8-47.el8_6.11*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpython3-0:3.6.8-47.el8_6.11*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpython3-0:3.6.8-47.el8_6.11*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpython3.11-0:3.11.2-2.el8_8.8*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpython3-0:3.6.8-51.el8_8.13*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpython3.11-0:3.11.2-2.el8_8.8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpython3-0:3.6.8-51.el8_8.13*
Red Hat Enterprise Linux 9RedHatpython3.12-0:3.12.12-4.el9_7.1*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.25-3.el9_7.1*
Red Hat Enterprise Linux 9RedHatpython3.11-0:3.11.13-5.1.el9_7*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.25-3.el9_7.1*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatpython3.9-0:3.9.10-4.el9_0.9*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatpython3.11-0:3.11.2-2.el9_2.10*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatpython3.9-0:3.9.16-1.el9_2.12*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpython3.9-0:3.9.18-3.el9_4.11*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpython3.12-0:3.12.1-4.el9_4.11*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpython3.11-0:3.11.7-1.el9_4.11*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatpython3.12-0:3.12.9-1.el9_6.6*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatpython3.9-0:3.9.21-2.el9_6.4*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-spyre-rhel9:1778244546*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-cuda-rhel9:1775680192*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-rocm-rhel9:1775680262*
Red Hat AI Inference Server 3.3RedHatrhaiis/model-opt-cuda-rhel9:1775749857*
Red Hat Ceph Storage 8RedHatrhceph/rhceph-8-rhel9:1774002867*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1775668717*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1775675922*
Red Hat Hardened ImagesRedHatpython3-13-main-3.13.13-1.hum1*
Red Hat Hardened ImagesRedHatpython3-14-main-3.14.4-1.hum1*
Red Hat Hardened ImagesRedHatpython3-11-main-3.11.15-4.hum1*
Red Hat Hardened ImagesRedHatpython3-12-main-3.12.13-3.hum1*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1773670073*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1773672059*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1773668803*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1773670137*
Python2.7Ubuntuesm-infra/xenial*
Python3.13Ubuntuupstream*
Python3.14Ubuntudevel*
Python3.14Ubunturesolute*
Python3.14Ubuntuupstream*
Python3.5Ubuntuesm-infra/xenial*

Potential Mitigations

References