Your message dated Sun, 30 Aug 2026 13:43:24 +0200
with message-id <[email protected]>
and subject line Re: Accepted python-zeep 4.3.3-1 (source) into unstable
has caused the Debian Bug report #1141819,
regarding python-zeep: CVE-2026-58501
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141819: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141819
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-zeep
Version: 4.3.2-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for python-zeep.
CVE-2026-58501[0]:
| Zeep is a Python SOAP client. From 4.0.0 before 4.3.3,
| Settings.forbid_external is defined but not enforced when parsing
| WSDL or XSD documents, allowing transitive xsd:import, xsd:include,
| wsdl:import, and lxml entity or DTD references to fetch attacker-
| chosen HTTP or HTTPS URLs. This issue is fixed in version 4.3.3.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-58501
https://www.cve.org/CVERecord?id=CVE-2026-58501
[1]
https://github.com/mvantellingen/python-zeep/security/advisories/GHSA-4cc2-g9w2-fhf6
[2]
https://github.com/mvantellingen/python-zeep/commit/83eb07bc6c84d841329d4f88856fecdba86f753e
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: python-zeep
Source-Version: 4.3.3-1
This fixes as well #1141819, closing manually.
On Sun, Aug 30, 2026 at 10:22:58AM +0000, Debian FTP Masters wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
> Format: 1.8
> Date: Sat, 29 Aug 2026 17:59:50 +0200
> Source: python-zeep
> Architecture: source
> Version: 4.3.3-1
> Distribution: unstable
> Urgency: high
> Maintainer: Debian Tryton Maintainers <[email protected]>
> Changed-By: Mathias Behrle <[email protected]>
> Changes:
> python-zeep (4.3.3-1) unstable; urgency=high
> .
> * Merging upstream version 4.3.3.
> This release fixes CVE-2026-58501:
> From 4.0.0 before 4.3.3,
> Settings.forbid_external is defined but not enforced when parsing
> WSDL or XSD documents, allowing transitive xsd:import, xsd:include,
> wsdl:import, and lxml entity or DTD references to fetch attacker-
> chosen HTTP or HTTPS URLs.
> * Update the dependency stack.
> Checksums-Sha1:
> e97a6ff89eb777bb47bfc02df1edacd3a0ecc60b 2540 python-zeep_4.3.3-1.dsc
> 4e3c6b7e2fccd8f8a080858e46bc353948365df4 167372 python-zeep_4.3.3.orig.tar.gz
> 2570ca957c2e0a2206238cf523a129363fc3e3b0 9112
> python-zeep_4.3.3-1.debian.tar.xz
> a391081524f2f6699edda4666db371605531d652 8331
> python-zeep_4.3.3-1_amd64.buildinfo
> Checksums-Sha256:
> 71e0866a2b9d6d06fee2499bc58e3c22a1450be756070e6624dcfcd3fc64aecf 2540
> python-zeep_4.3.3-1.dsc
> 99d5059f92f721020998695fd9c85289ccb03ec5a2398ad49c6dbe43f19cfb94 167372
> python-zeep_4.3.3.orig.tar.gz
> 6f3cf2bf2d24ca32c950d069856aa0685c046c5049bea6713431698073e4617e 9112
> python-zeep_4.3.3-1.debian.tar.xz
> 00e8c680c848f96417153f01137d5b8b266ac47bb0e463b3894f3bef247d5a39 8331
> python-zeep_4.3.3-1_amd64.buildinfo
> Files:
> 877b4a13ed9598e100b5f77792d4c327 2540 python optional python-zeep_4.3.3-1.dsc
> cc13ce426f534dfa98478c6a8e7a6152 167372 python optional
> python-zeep_4.3.3.orig.tar.gz
> b4da185330d841bf7b2d468e4e6fd502 9112 python optional
> python-zeep_4.3.3-1.debian.tar.xz
> 0f809a902bd22686b22d8263b5f3d983 8331 python optional
> python-zeep_4.3.3-1_amd64.buildinfo
>
> -----BEGIN PGP SIGNATURE-----
> Comment: Signed by Mathias Behrle
>
> iQIzBAEBCgAdFiEErCl+XEa50LYccXaB1tCb5IQFu/YFAmqUARMACgkQ1tCb5IQF
> u/aPNxAAhMWPI1IulSiFiSjsY0w6XiY2CeXayGjyPjFgt4y9IHV6uExPJ+RN+6Wy
> 7ls/PPd4gbE13XuWK30JuTmouFwQqABfaM6O5ks4c0Mb/lFhIuVI5Lu7vvddanXB
> ZWtF4yxM50YzUdBfOAM4y5LjefIvYHTltWB48eVD7/X/qpuzgiPaqZ0CqtOK8/i8
> HSZ/hjxw/NbA65ZwgN1gJ1HFh0sDazMKis8syEVel42222ScC7WtZ+dpPh5Ig0dk
> 7SzAUtu5pJiO5sM/YQbRdPrZNN4Mwle+5XBsVkuQL0AegRvW5Gmt8qXwtnJKzfJE
> GJxslaxSZBsnhKtoAitzIgqDCYDivT4R6oGBkGM71OOc5s0m86CVkrBmKIzUqJ82
> 7cQGbK0Pg5RtSTjLEVvctWSkUQb0MScoGc/bYhieUv92fzO5uifAXt+cOGfQxcut
> DdfZpBgHHrqqjn4x9NHvnV0iaUb356vNGD6SJ9kD5izNHBzEjWLGRq2aq+cPqxo0
> SLNGYFLTMuIxDPCWhm6Mx459VEG915rwU71VzSgynNuY6YFxguyDmbgk1zvlE4iV
> dP6T9SriJQL9V5Ba0G+ElC+9w/Hs89PmnnJtQwKHRnm0pWvWxF9QlnmcysG5iMnj
> s6xYmZA52tT7opReQ8nqDB9Ew+sMb0TbIC01Lj28t0n1BufC22k=
> =8vJq
> -----END PGP SIGNATURE-----
--- End Message ---