Echo: python-3.10: security update to 3.10.17-e1python-3.9: security update to 3.9.22-e1python3.11: security update to 3.11.2-6+deb12u5-e1python3.12: security update to 3.12.4python3.13: security update to 3.13.0b2python3.9: security update to 3.9.21-e3

low Tenable Self-Hosted Container Security Plugin ID 460656

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- During an address list folding when a separating comma ends up on a folded line and that line is to be
unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the
separating comma remains a plan comma. This can result in the address header being misinterpreted by some
mail servers. (CVE-2025-1795)

Solution

Update the python-3.10 library and its related packages to version 3.10.17-e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-1795

Plugin Details

Severity: Low

ID: 460656

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2025-1795

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.3

Threat Score: 0.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/29/2026

Vulnerability Publication Date: 2/26/2025

Reference Information

CVE: CVE-2025-1795