[Git][security-tracker-team/security-tracker][master] Add new python issue

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 06:13:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bb15c238 by Salvatore Bonaccorso at 2026-08-18T07:12:56+02:00
Add new python issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11581,7 +11581,22 @@ CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and Ab
 CVE-2026-19278 (A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine ( ...)
 	NOT-FOR-US: Red Hat Advanced Cluster Security
 CVE-2026-18503 (Attacker-controlled CSV samples can trigger super-linear  regular-expr ...)
-	TODO: check
+	- python3.15 3.15.0~rc1-1
+	- python3.14 3.14.7-1
+	- python3.13 3.13.15-1
+	- python3.11 <removed>
+	- python3.9 <removed>
+	- python2.7 <removed>
+	- pypy3 <unfixed>
+	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
+	NOTE: https://github.com/python/cpython/issues/98820
+	NOTE: https://github.com/python/cpython/pull/153694
+	NOTE: Fixed by: https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9 (v3.15.0rc1)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a (v3.14.7)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b (v3.13.15)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82 (v3.12.14)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024 (v3.11.16)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4 (v3.10.21)
 CVE-2026-18478 (Magnolia CMS is vulnerable to Stored XSS in import functionality. An a ...)
 	NOT-FOR-US: Magnolia CMS
 CVE-2026-18412 (OpenCart extensions are uploaded as zip files with .ocmod.zip extensio ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb15c238e0df1852e63208ca63c925302169f06e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb15c238e0df1852e63208ca63c925302169f06e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/b54115ae/attachment.htm>


More information about the debian-security-tracker-commits mailing list