When folding a long comment in an email header containing...
Moderate severity
Unreviewed
Published
Jan 21, 2026
to the GitHub Advisory Database
•
Updated Mar 3, 2026
Description
Published by the National Vulnerability Database
Jan 20, 2026
Published to the GitHub Advisory Database
Jan 21, 2026
Last updated
Mar 3, 2026
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
References