CVE-2026-1299

EUVD-2026-4272
The 
email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when 
serializing an email message allowing for header injection when an email
 is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PSFCNA
6 MEDIUM
NETWORK
LOW
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pythoncpython
𝑥
< 3.10.20
CNA
pythoncpython
3.11.0 ≤
𝑥
< 3.11.15
CNA
pythoncpython
3.12.0 ≤
𝑥
< 3.12.13
CNA
pythoncpython
3.13.0 ≤
𝑥
< 3.13.12
CNA
pythoncpython
3.14.0 ≤
𝑥
< 3.14.3
CNA
Debian logo
Debian Releases
Debian Product
Codename
pypy3
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
python3.11
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
postponed
trixie
no-dsa
python3.13
bookworm
no-dsa
bullseye
postponed
forky
3.13.12-1
fixed
sid
3.13.12-1
fixed
trixie
vulnerable
python3.14
bookworm
no-dsa
bullseye
postponed
forky
3.14.3-3
fixed
sid
3.14.3-5
fixed
trixie
no-dsa
python3.9
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
3.9.2-1+deb11u5
fixed
trixie
no-dsa