CVE-2024-6923
published 2024-08-01CVE-2024-6923: There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message…
PriorityP428medium5.5CVSS 3.1
AVNACLPRLUIRSUCLILAL
EPSS
0.78%
51.8th percentile
There is a MEDIUM severity vulnerability affecting CPython.
The
email module didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python2.7 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.11 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.13 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.9 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| msrc | azl3_python3_3.12.3-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| python_software_foundation | cpython | < 3.8.20 | 3.8.20 |
| python_software_foundation | cpython | >= 3.10.0 < 3.10.15 | 3.10.15 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.10 | 3.11.10 |
| python_software_foundation | cpython | >= 3.12.0 < 3.12.5 | 3.12.5 |
| python_software_foundation | cpython | >= 3.13.0a1 < 3.13.0rc2 | 3.13.0rc2 |
| python_software_foundation | cpython | >= 3.9.0 < 3.9.20 | 3.9.20 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python 2.7 regression
vendor_ubuntu·2025-09-29·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python 2.7 regression
Title: Python 2.7 regression
Summary: USN-7015-4 introduced a regression in Python 2.7
USN-7015-4 fixed vulnerabilities in Python. It was discovered that the fix
for CVE-2023-27043 for python2.7 was incorrectly applied on Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
Ubuntu
Python regressions
vendor_ubuntu·2024-11-22·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python regressions
Title: Python regressions
Summary: USN-7015-5 caused some regressions in Python.
USN-7015-5 fixed vulnerabilities in python2.7. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted n
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-11-19·CVSS 5.3
CVE-2024-6232 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for CVE-2024-6232 and CVE-2024-6923 for python2.7
in Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
Ubuntu
Python vulnerability
vendor_ubuntu·2024-10-14·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python vulnerability
Title: Python vulnerability
Summary: Python could me made to bypass some restrictions if it received specially
crafted input.
USN-7015-1 fixed several vulnerabilities in Python. This update provides the
corresponding update for CVE-2023-27043 for python2.7 and python3.5 in
Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered th
Ubuntu
Python vulnerability
vendor_ubuntu·2024-10-01·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python vulnerability
Title: Python vulnerability
Summary: Python could be made to bypass some restrictions if it received specially
crafted input.
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding updates for CVE-2023-27043 for python2.7 in Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and for
python3.5 in Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to cons
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-09-16·CVSS 5.3
CVE-2024-6923 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could possibly
use this issue to bypass certain protection mechanisms. (CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue to
cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly use this issue to
perform header injection. (CVE-2024-6923)
It was discovered that the Python http.cookies module incorrectly ha
Microsoft
Email header injection due to unquoted newlines
vendor_msrc·2024-08-13·CVSS 5.5
CVE-2024-6923 [MEDIUM] CWE-94 Email header injection due to unquoted newlines
Email header injection due to unquoted newlines
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.c
Red Hat
cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection
vendor_redhat·2024-08-01·CVSS 5.5
CVE-2024-6923 [MEDIUM] cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection
cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection
There is a MEDIUM severity vulnerability affecting CPython.
The
email module didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized.
A vulnerability was found in the email module that uses Python language. The email module doesn't properly quote new lines in email headers. This flaw allows an attacker to inject email headers that could, among other possibilities, add hidden email destinations or inject content into the email, impacting data confidentiality and integrity.
Statement: Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they jus
Debian
CVE-2024-6923: pypy3 - There is a MEDIUM severity vulnerability affecting CPython. The email module d...
vendor_debian·2024·CVSS 5.5
CVE-2024-6923 [MEDIUM] CVE-2024-6923: pypy3 - There is a MEDIUM severity vulnerability affecting CPython. The email module d...
There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u5)
forky: resolved (fixed in 7.3.18+dfsg-1)
sid: resolved (fixed in 7.3.18+dfsg-1)
trixie: resolved (fixed in 7.3.18+dfsg-1)
OSV
python2.7 regression
osv·2025-09-29·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7 regression
python2.7 regression
USN-7015-4 fixed vulnerabilities in Python. It was discovered that the fix
for CVE-2023-27043 for python2.7 was incorrectly applied on Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module inc
OSV
python2.7 regresssions
osv·2024-11-22·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7 regresssions
python2.7 regresssions
USN-7015-5 fixed vulnerabilities in python2.7. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly
OSV
python2.7 vulnerabilities
osv·2024-11-19·CVSS 5.3
CVE-2024-6232 [MEDIUM] python2.7 vulnerabilities
python2.7 vulnerabilities
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for CVE-2024-6232 and CVE-2024-6923 for python2.7
in Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email mod
OSV
python2.7, python3.5 vulnerability
osv·2024-10-14·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7, python3.5 vulnerability
python2.7, python3.5 vulnerability
USN-7015-1 fixed several vulnerabilities in Python. This update provides the
corresponding update for CVE-2023-27043 for python2.7 and python3.5 in
Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker
OSV
python2.7, python3.5 vulnerability
osv·2024-10-01·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7, python3.5 vulnerability
python2.7, python3.5 vulnerability
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding updates for CVE-2023-27043 for python2.7 in Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and for
python3.5 in Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the P
OSV
python3.10, python3.12, python3.8 vulnerabilities
osv·2024-09-16·CVSS 5.3
CVE-2023-27043 [MEDIUM] python3.10, python3.12, python3.8 vulnerabilities
python3.10, python3.12, python3.8 vulnerabilities
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could possibly
use this issue to bypass certain protection mechanisms. (CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue to
cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly use this issue to
perform header injection. (CVE-2024-6923)
It was discovered that the Python http.cookies module incorrectly handled
parsing cookies that contained
GHSA
GHSA-87qc-q3w7-7m8w: There is a MEDIUM severity vulnerability affecting CPython
ghsa_unreviewed·2024-08-01
CVE-2024-6923 [MEDIUM] CWE-94 GHSA-87qc-q3w7-7m8w: There is a MEDIUM severity vulnerability affecting CPython
There is a MEDIUM severity vulnerability affecting CPython.
The
email module didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized.
OSV
CVE-2024-6923: There is a MEDIUM severity vulnerability affecting CPython
osv·2024-08-01·CVSS 5.5
CVE-2024-6923 [MEDIUM] CVE-2024-6923: There is a MEDIUM severity vulnerability affecting CPython
There is a MEDIUM severity vulnerability affecting CPython.
The
email module didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized.
OSV
CVE-2024-6923: There is a MEDIUM severity vulnerability affecting CPython
osv·2024-08-01·CVSS 5.5
CVE-2024-6923 [MEDIUM] CVE-2024-6923: There is a MEDIUM severity vulnerability affecting CPython
There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147https://github.com/python/cpython/commit/097633981879b3c9de9a1dd120d3aa585ecc2384https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0https://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533https://github.com/python/cpython/issues/121650https://github.com/python/cpython/pull/122233https://mail.python.org/archives/list/[email protected]/thread/QH3BUOE2DYQBWP7NAQ7UNHPPOELKISRW/http://www.openwall.com/lists/oss-security/2024/08/01/3http://www.openwall.com/lists/oss-security/2024/08/02/2https://lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2025/01/msg00005.htmlhttps://security.netapp.com/advisory/ntap-20240926-0003/
2024-08-01
Published