CVE Feed

    Dashboard / CVE / CVE-2025-13033

    CVE-2025-13033

    A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.

    Published:Oct 7, 2025
    Last Modified:May 11, 2026
    EPS:Nov 14, 2025
    EPSS Score:0.00031
    CVSS Score:7.5

    Affected Products

    Vendor
    Redhat
    Product
    Acm
    Vendor
    Redhat
    Product
    Ceph Storage
    Vendor
    Redhat
    Product
    Rhdh

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High