[Git][security-tracker-team/security-tracker][master] Add CVE-2026-15308/python

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 25 06:47:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3736b64a by Salvatore Bonaccorso at 2026-07-25T07:46:42+02:00
Add CVE-2026-15308/python

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14783,7 +14783,17 @@ CVE-2026-1989 (Authorization bypass through User-Controlled key vulnerability in
 CVE-2026-1365 (Insertion of sensitive information into sent data vulnerability in Say ...)
 	NOT-FOR-US: OSOS
 CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...)
-	TODO: check
+	- python3.14 <unfixed>
+	- python3.13 <unfixed>
+	- python3.11 <removed>
+	- python3.9 <removed>
+	- python2.7 <removed>
+	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/
+	NOTE: https://github.com/python/cpython/issues/153030
+	NOTE: https://github.com/python/cpython/pull/153031
+	NOTE: https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd (v3.15.0b4)
+	NOTE: https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 (3.14 branch)
+	NOTE: https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced (3.13 branch)
 CVE-2026-15204 (A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515 ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-15202 (A security vulnerability has been detected in YzmCMS up to 7.5. Affect ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3736b64a0f4d1ce76b6e4277e23628c72539b984

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3736b64a0f4d1ce76b6e4277e23628c72539b984
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/0a71f6a3/attachment.htm>


More information about the debian-security-tracker-commits mailing list