[Git][security-tracker-team/security-tracker][master] Triage CVE-2026-15806, CVE-2026-17084 & CVE-2026-18503 in python2.7 for bookworm LTS.
Chris Lamb (@lamby)
lamby at debian.org
Wed Aug 19 23:26:48 BST 2026
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
615d0345 by Chris Lamb at 2026-08-19T15:26:36-07:00
Triage CVE-2026-15806, CVE-2026-17084 & CVE-2026-18503 in python2.7 for bookworm LTS.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3920,6 +3920,7 @@ CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/
NOTE: https://github.com/python/cpython/issues/155292
@@ -3935,6 +3936,7 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along wi
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/
NOTE: https://github.com/python/cpython/issues/155694
@@ -16006,6 +16008,7 @@ CVE-2026-18503 (Attacker-controlled CSV samples can trigger super-linear regula
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/615d0345fd1f74296ba331492d197abf462272fb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/615d0345fd1f74296ba331492d197abf462272fb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/be6c2220/attachment.htm>
More information about the debian-security-tracker-commits
mailing list