Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a966cd4f by Sylvain Beucler at 2026-05-18T12:47:17+02:00
CVE-2026-7210/py*: reference libexpat pre-req CVE

- - - - -
2d30cec1 by Sylvain Beucler at 2026-05-18T12:47:20+02:00
CVE-2025-69534,CVE-2026-1502,CVE-2026-6019/python3.9: bullseye postponed

aligning with other dists

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4235,8 +4235,8 @@ CVE-2026-7210 (`xml.parsers.expat` and 
`xml.etree.ElementTree` use insufficient
        NOTE: 
https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4
 (main)
        NOTE: https://github.com/python/cpython/pull/149645 (3.15)
        NOTE: https://github.com/python/cpython/pull/149646 (3.14)
-       NOTE: Fully mitigating this vulnerability requires both updating 
libexpat to
-       NOTE: 2.8.0 or later and applying the python patch for CVE-2026-7210.
+       NOTE: Fully mitigating this vulnerability requires fixing both libexpat
+       NOTE: (CVE-2026-41080) and applying the python patch for CVE-2026-7210.
 CVE-2026-6956 (ATutor is vulnerable to Reflected XSS in/install/install.php 
endpoint. ...)
        NOT-FOR-US: ATutor
 CVE-2026-6909 (ATutor is vulnerable to Reflected XSS in/install/upgrade.php 
endpoint. ...)
@@ -15417,6 +15417,7 @@ CVE-2026-6019 (http.cookies.Morsel.js_output() returns 
an inline <script> snippe
        - python3.11 <removed>
        [bookworm] - python3.11 <no-dsa> (Minor issue)
        - python3.9 <removed>
+       [bullseye] - python3.9 <postponed> (Minor issue, unused function)
        - pypy3 <unfixed> (bug #1135116)
        [trixie] - pypy3 <no-dsa> (Minor issue)
        [bookworm] - pypy3 <no-dsa> (Minor issue)
@@ -21989,6 +21990,7 @@ CVE-2026-1502 (CR/LF bytes were not rejected by HTTP 
client proxy tunnel headers
        - python3.11 <removed>
        [bookworm] - python3.11 <no-dsa> (Minor issue)
        - python3.9 <removed>
+       [bullseye] - python3.9 <no-dsa> (Minor issue, response splitting)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
        - pypy3 7.3.22+dfsg-1
@@ -42103,6 +42105,7 @@ CVE-2025-69534 (Python-Markdown version 3.8 contain a 
vulnerability where malfor
        - python3.11 <removed>
        [bookworm] - python3.11 <no-dsa> (Minor issue)
        - python3.9 <removed>
+       [bullseye] - python3.9 <postponed> (Minor issue, DoS)
        - pypy3 <unfixed>
        [trixie] - pypy3 <no-dsa> (Minor issue)
        [bookworm] - pypy3 <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d4c43ab1edaa59bb37770c3d0e0202b39e939fee...2d30cec1cd6b25c56036753e4274271c0acd388a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d4c43ab1edaa59bb37770c3d0e0202b39e939fee...2d30cec1cd6b25c56036753e4274271c0acd388a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to