CVE-2025-11468
Email Client - Info Disclosure
Title source: llmDescription
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
Scores
EPSS
0.0004
EPSS Percentile
13.4%
Classification
CWE
CWE-93
Status
draft
Timeline
Published
Jan 20, 2026
Tracked Since
Feb 18, 2026