CVE-2025-15367

POP3 command injection in user-controlled commands

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.


We have discovered 470 live websites that are affected by CVE-2025-15367.

Run a Free Instant Scan




Affected Software

Product  CPython
Category Programming Languages
Vulnerable Domains470 live websites (100% of CPython install base)
Vulnerable Versions
  • from 0 through 3.15
Vulnerable Versions Count72 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')



Details

  • Published - Jan 20, 2026
  • Updated - Feb 26, 2026

Credits

  • Omar M. Hasan (reporter)

Website Distribution by Country

Number of websites using CVE-2025-15367
United States150 websites



Germany59 websites
Singapore28 websites
India22 websites
France19 websites
Russia15 websites
China13 websites
Brazil11 websites
GB11 websites
Australia10 websites

Website Distribution by TLD

Number of websites using CVE-2025-15367
.com160 websites
.org47 websites
.dk26 websites
.de20 websites
.net19 websites
.nl9 websites
.edu8 websites
.ru8 websites
.fr7 websites
.ch7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-15367

Top websites that are affected by CVE-2025-15367. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*********.com Netherlands***,***
*******.***.org Germany***,***
*****.org Germany***,***
***********.org Australia***,***
****.***********.***.au Australia***,***
*******.org Australia***,***
*****.*****.de Germany***,***
********.***.***.gr Greece***,***
***.********.it Italy***,***
See full domain list

FAQ

CVE-2025-15367 is Improper Neutralization of Special Elements used in a Command ('Command Injection') in CPython
A total of 470 websites have been identified as vulnerable to CVE-2025-15367, based on global website indexing conducted by WebTechSurvey.
The CPython is affected by the CVE-2025-15367 vulnerability.
CPython versions up to 3.15 are vulnerable to CVE-2025-15367.
CVE-2025-15367 is resolved in version 3.15 of CPython.