[Git][security-tracker-team/security-tracker][master] Add CVE-2026-15806/python

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 07:27:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dcdf6457 by Salvatore Bonaccorso at 2026-08-19T08:27:06+02:00
Add CVE-2026-15806/python

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1069,7 +1069,20 @@ CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454
 CVE-2026-16309 (Authorization bypass through User-Controlled key vulnerability in Neti ...)
 	TODO: check
 CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along with its ...)
-	TODO: check
+	- python3.15 <unfixed>
+	- python3.14 <unfixed>
+	- python3.13 <unfixed>
+	- python3.11 <removed>
+	- python3.9 <removed>
+	- python2.7 <removed>
+	- pypy3 <unfixed>
+	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/
+	NOTE: https://github.com/python/cpython/issues/155694
+	NOTE: https://github.com/python/cpython/pull/155696
+	NOTE: Fixed by: https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce (main)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6 (3.15 branch)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8 (3.14 branch)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce (3.13 branch)
 CVE-2026-15585 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	TODO: check
 CVE-2026-12564 (A flaw was found in the AAP Controller's HashiCorp Vault credential pl ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dcdf645745fbcd570fa42a1472d5f8e16b1c3419

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dcdf645745fbcd570fa42a1472d5f8e16b1c3419
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/a976351e/attachment.htm>


More information about the debian-security-tracker-commits mailing list