CVE-2025-1795 - CVE House
Back to Database
Status published Low CVE-2025-1795

Mishandling of comma during folding and unicode-encoding of email headers

Vulnerability Description

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1795

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Python Software Foundation

View all reports →

Affected Software

CPython
Vulnerable Versions:
0, 3.11.0, 3.12.0, 3.13.0a1

Timeline

Official Publish: February 28th, 2025
Last Modified: April 21st, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.