[Git][security-tracker-team/security-tracker][master] followup fix for CVE-2026-6019

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Jun 10 22:28:54 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
792521e5 by Moritz Muehlenhoff at 2026-06-10T23:28:33+02:00
followup fix for CVE-2026-6019

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32719,8 +32719,11 @@ CVE-2026-6019 (http.cookies.Morsel.js_output() returns an inline <script> snippe
 	NOTE: https://github.com/python/cpython/pull/148848
 	NOTE: Fixed by: https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104 (main branch)
 	NOTE: Fixed by: https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8 (v3.14.5rc1)
-	NOTE: Fixed by: https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c (3.13 branch)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c (v3.13.14)
 	NOTE: Follow-up: https://github.com/python/cpython/issues/149144
+	NOTE: Follow-up fix: https://github.com/python/cpython/commit/461b1d96313de02992d284c1782be9aff24586c9 (main branch)
+	NOTE: Follow-up fix: https://github.com/python/cpython/commit/4f17f6e04534d93fbd23862f9f290d3a281ab30b (v3.14.6)
+	NOTE: Follow-up fix: https://github.com/python/cpython/commit/e7d4c3ff421916986223690a8425d2383f6f3802 (v3.13.14)
 CVE-2026-5935 (IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9 ...)
 	NOT-FOR-US: IBM
 CVE-2026-5926 (IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Secur ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/792521e56fa149bbb57a329d78d319b6d989a426

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/792521e56fa149bbb57a329d78d319b6d989a426
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260610/9970b14e/attachment.htm>


More information about the debian-security-tracker-commits mailing list