Improper Handling of Inconsistent Special Elements Affecting python package, versions [,3.10.17)[3.11.0-a1,3.11.9)[3.12.0-a1,3.12.3)[3.13.0-a1,3.13.0-a5)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.24% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PYTHON-9055445
  • published3 Mar 2025
  • disclosed28 Feb 2025
  • creditThomas Weißschuh

Introduced: 28 Feb 2025

CVE-2025-1795  (opens in a new tab)
CWE-168  (opens in a new tab)

How to fix?

Upgrade python to version 3.10.17, 3.11.9, 3.12.3, 3.13.0-a5 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Inconsistent Special Elements due to mishandling of comma during folding and unicode-encoding of email headers. An attacker can cause the address header to be misinterpreted by some mail servers by exploiting the incorrect unicode-encoding of the separator when it ends up in a folded line.

CVSS Base Scores

version 4.0
version 3.1