[Git][security-tracker-team/security-tracker][master] Add two new python-urllib3 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Dec 5 20:40:30 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
df1e5ef7 by Salvatore Bonaccorso at 2025-12-05T21:39:55+01:00
Add two new python-urllib3 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -63,9 +63,13 @@ CVE-2025-66511 (Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0
 CVE-2025-66510 (Nextcloud Server is a self hosted personal cloud system. In Nextcloud  ...)
 	TODO: check
 CVE-2025-66471 (urllib3 is a user-friendly HTTP client library for Python. Starting in ...)
-	TODO: check
+	- python-urllib3 <unfixed>
+	NOTE: https://www.openwall.com/lists/oss-security/2025/12/05/4
+	NOTE: https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37
 CVE-2025-66418 (urllib3 is a user-friendly HTTP client library for Python. Starting in ...)
-	TODO: check
+	- python-urllib3 <unfixed>
+	NOTE: https://www.openwall.com/lists/oss-security/2025/12/05/4
+	NOTE: https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53
 CVE-2025-65897 (zdh_web is a data collection, processing, monitoring, scheduling, and  ...)
 	TODO: check
 CVE-2025-65879 (Warehouse Management System 1.2 contains an authenticated arbitrary fi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/df1e5ef7ae3f2e8a09955fad562f9d0fb2437469

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/df1e5ef7ae3f2e8a09955fad562f9d0fb2437469
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251205/3aac98f2/attachment.htm>


More information about the debian-security-tracker-commits mailing list