[Git][security-tracker-team/security-tracker][master] python3.13 fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Aug 11 13:37:07 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d6d06cae by Moritz Muehlenhoff at 2026-08-11T14:36:44+02:00
python3.13 fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11336,7 +11336,7 @@ CVE-2026-7187 (Missing authentication for critical function vulnerability in Uni
 	NOT-FOR-US: UKBS
 CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O ...)
 	- python3.14 <unfixed>
-	- python3.13 <unfixed>
+	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
 	- python3.9 <removed>
@@ -29951,7 +29951,7 @@ CVE-2026-1365 (Insertion of sensitive information into sent data vulnerability i
 	NOT-FOR-US: OSOS
 CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...)
 	- python3.14 <unfixed>
-	- python3.13 <unfixed>
+	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
 	[bookworm] - python3.11 <postponed> (CPU-only DoS; the quadratic rescan needs feed() driven in small chunks, a single feed() of the whole document stays linear; no upstream fix for this branch)
@@ -37083,7 +37083,7 @@ CVE-2026-4629 (A flaw was found in Keycloak. A highly privileged user with `mana
 	- keycloak <itp> (bug #1088287)
 CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not passed  ...)
 	- python3.14 <unfixed>
-	- python3.13 <unfixed>
+	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <not-affected> (Vulnerable code didn't get backported to the version in Bookworm)
 	- python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2; extract() has no filter parameter)
@@ -43279,7 +43279,7 @@ CVE-2026-11997 (The Bulk SEO Image plugin for WordPress is vulnerable to Cross-S
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming mode" ...)
 	- python3.14 <unfixed>
-	- python3.13 <unfixed>
+	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
 	[bookworm] - python3.11 <postponed> (Minor issue)
@@ -43813,7 +43813,7 @@ CVE-2026-10521 (An high privileged remote attacker can access a hidden configura
 	NOT-FOR-US: MB connect
 CVE-2026-0864 (When using the "configparser" module to write configuration files cont ...)
 	- python3.14 <unfixed>
-	- python3.13 <unfixed>
+	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
 	[bookworm] - python3.11 <postponed> (Minor issue)
@@ -43935,7 +43935,7 @@ CVE-2026-44517
 	NOTE: Fixed by: https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49 (v1.43.2)
 CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be bypasse ...)
 	- python3.14 <unfixed>
-	- python3.13 <unfixed>
+	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
 	[bookworm] - python3.11 <postponed> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6d06cae9b18f257631f5368517d41ddc458923a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6d06cae9b18f257631f5368517d41ddc458923a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/c7f94993/attachment.htm>


More information about the debian-security-tracker-commits mailing list