CVE-2025-15366

IMAP command injection in user-controlled commands

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.


We have discovered 486 live websites that are affected by CVE-2025-15366.

Run a Free Instant Scan




Affected Software

Product  CPython
Category Programming Languages
Vulnerable Domains486 live websites (100% of CPython install base)
Vulnerable Versions
  • from 0 through 3.15
Vulnerable Versions Count79 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')



Details

  • Published - Jan 20, 2026
  • Updated - Jan 22, 2026

Credits

  • Omar M. Hasan (reporter)

Website Distribution by Country

Number of websites using CVE-2025-15366
United States162 websites



Germany60 websites
Singapore26 websites
Russia25 websites
France19 websites
India16 websites
GB13 websites
China12 websites
Brazil11 websites
Switzerland11 websites

Website Distribution by TLD

Number of websites using CVE-2025-15366
.com168 websites
.org47 websites
.dk25 websites
.de20 websites
.net17 websites
.ru12 websites
.nl9 websites
.edu9 websites
.fr8 websites
.ch7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-15366

Top websites that are affected by CVE-2025-15366. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*******.***.org Germany***,***
*****.org Germany***,***
****.***********.***.au Australia***,***
********.org Nepal***,***
*****.*****.de Germany***,***
**************.com United States***,***
********.***.***.gr Greece***,***
***.********.it Italy***,***
*************.nl Netherlands***,***
See full domain list

FAQ

CVE-2025-15366 is Improper Neutralization of Special Elements used in a Command ('Command Injection') in CPython
A total of 486 websites have been identified as vulnerable to CVE-2025-15366, based on global website indexing conducted by WebTechSurvey.
The CPython is affected by the CVE-2025-15366 vulnerability.
CPython versions up to 3.15 are vulnerable to CVE-2025-15366.
CVE-2025-15366 is resolved in version 3.15 of CPython.