CVE-2026-1299

Updated: 2026-02-22 04:13:36.355094

Description:

The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 8.4 ELS python3 3.6.8 7.1 HIGH Released CLSA-2026:1771494614 2026-02-19 12:21:35
CentOS 8.4 ELS python2 2.7.18 7.1 HIGH In Testing 2026-02-23 18:33:56
CentOS 8.5 ELS python2 2.7.18 7.1 HIGH Released CLSA-2026:1771925958 2026-02-24 11:39:05
CentOS 8.5 ELS python3 3.6.8 7.1 HIGH Released CLSA-2026:1771499011 2026-02-19 12:21:36
CentOS Stream 8 ELS python2 2.7.18 7.1 HIGH In Testing 2026-02-23 18:33:57