[Git][security-tracker-team/security-tracker][master] python3.14 fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Aug 11 13:47:00 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
17ce1544 by Moritz Muehlenhoff at 2026-08-11T14:46:51+02:00
python3.14 fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11340,7 +11340,7 @@ CVE-2026-7362 (IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.
 CVE-2026-7187 (Missing authentication for critical function vulnerability in Universa ...)
 	NOT-FOR-US: UKBS
 CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O ...)
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-1
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -11356,6 +11356,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
 	NOTE: https://github.com/python/cpython/issues/152674
 	NOTE: https://github.com/python/cpython/pull/152676
 	NOTE: https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0 (main)
+	NOTE: https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3 (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db (v3.13.15)
 CVE-2026-67185 (TinyWeb through 0.0.8 contains a path traversal vulnerability that all ...)
 	NOT-FOR-US: TinyWeb
@@ -29955,7 +29956,7 @@ CVE-2026-1989 (Authorization bypass through User-Controlled key vulnerability in
 CVE-2026-1365 (Insertion of sensitive information into sent data vulnerability in Say ...)
 	NOT-FOR-US: OSOS
 CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...)
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-1
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -29968,7 +29969,7 @@ CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for
 	NOTE: https://github.com/python/cpython/issues/153030
 	NOTE: https://github.com/python/cpython/pull/153031
 	NOTE: https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd (v3.15.0b4)
-	NOTE: https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 (3.14 branch)
+	NOTE: https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced (v3.13.15)
 CVE-2026-15204 (A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515 ...)
 	NOT-FOR-US: TOTOLINK
@@ -37087,7 +37088,7 @@ CVE-2026-50734 (Memory Allocation with Excessive Size Value vulnerability in Apa
 CVE-2026-4629 (A flaw was found in Keycloak. A highly privileged user with `manage-cl ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not passed  ...)
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-1
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <not-affected> (Vulnerable code didn't get backported to the version in Bookworm)
@@ -37101,8 +37102,8 @@ CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not pa
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/
 	NOTE: https://github.com/python/cpython/issues/151987
 	NOTE: https://github.com/python/cpython/pull/151988
-	NOTE: https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301 (3.15 branch)
-	NOTE: https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0 (3.14 branch)
+	NOTE: https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301 (v3.15.0b4)
+	NOTE: https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0 (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e (v3.13.15)
 	NOTE: Same code situation as with CVE-2025-4435.
 CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ.  An authentic ...)
@@ -43283,7 +43284,7 @@ CVE-2026-12094 (The Advanced Contact Form 7 - Compact DB plugin for WordPress is
 CVE-2026-11997 (The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Re ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming mode" ...)
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-1
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -43298,7 +43299,7 @@ CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming
 	[bullseye] - pypy3 <postponed> (Minor issue; CPU DoS in tarfile._Stream.seek() looping over attacker-declared block count past EOF, needs a crafted archive opened in streaming mode)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/
 	NOTE: https://github.com/python/cpython/issues/151981
-	NOTE: https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec (3.14)
+	NOTE: https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9 (v3.13.15)
 CVE-2026-11820 (A flaw was found in the community.general Ansible collection's nexmo m ...)
 	NOT-FOR-US: Red Hat
@@ -43817,7 +43818,7 @@ CVE-2026-10609 (A missing authorization flaw was found in the OpenShift Cluster
 CVE-2026-10521 (An high privileged remote attacker can access a hidden configuration m ...)
 	NOT-FOR-US: MB connect
 CVE-2026-0864 (When using the "configparser" module to write configuration files cont ...)
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-1
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -43836,6 +43837,7 @@ CVE-2026-0864 (When using the "configparser" module to write configuration files
 	NOTE: https://github.com/python/cpython/pull/152004 (3.13)
 	NOTE: https://github.com/python/cpython/pull/152006 (3.11)
 	NOTE: https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f (main)
+	NOTE: https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98 (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8 (v3.13.15)
 CVE-2025-71382 (MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerabili ...)
 	- mupdf 1.27.0+ds1-2
@@ -43939,7 +43941,7 @@ CVE-2026-44517
 	NOTE: https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
 	NOTE: Fixed by: https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49 (v1.43.2)
 CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be bypasse ...)
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-1
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -43954,8 +43956,8 @@ CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be b
 	[bullseye] - pypy3 <not-affected> (Extraction filters (PEP 706) absent in the embedded CPython stdlib; tarfile.extractall() has no filter parameter)
 	NOTE: https://github.com/python/cpython/issues/151558
 	NOTE: https://github.com/python/cpython/pull/151559
-	NOTE: https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df (3.15 branch)
-	NOTE: https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c (3.14 branch)
+	NOTE: https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df (v3.15.0b4)
+	NOTE: https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde (v3.13.15)
 CVE-2026-55556
 	- rsyslog 8.2604.0-1 (unimportant)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17ce1544d06f8a9b0d3f82fa4e124d3cb204a470

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17ce1544d06f8a9b0d3f82fa4e124d3cb204a470
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/d1e80532/attachment.htm>


More information about the debian-security-tracker-commits mailing list