It is possible to inject email headers using CR or LF character.
The fix disallows CR and LF characters in email.headerregistry.Address arguments to guard against header injection attacks.
email.headerregistry.Address
{ "cwe_ids": [] }
"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2019-16.json"