[Git][security-tracker-team/security-tracker][master] new postorius issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu May 7 22:37:37 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2a19c2c9 by Moritz Muehlenhoff at 2026-05-07T23:36:45+02:00
new postorius issues

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -66,7 +66,9 @@ CVE-2026-5786 (An Improper Access Control vulnerability in Ivanti EPMM before ve
 CVE-2026-5784 (Improper neutralization of input during web page generation ('cross-si ...)
 	NOT-FOR-US: DivvyDrive
 CVE-2026-44742 (Postorius through 1.3.13 does not escape HTML in the message subject w ...)
-	TODO: check
+	- postorius <unfixed>
+	NOTE: https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b
+	NOTE: https://gitlab.com/mailman/postorius/-/merge_requests/972
 CVE-2026-44407 (A remote denial-of-service vulnerability exists in the ZTE Cloud PC cl ...)
 	NOT-FOR-US: ZTE
 CVE-2026-44406 (ZTE Cloud PC clientuSmartView contains a DLL hijacking vulnerability;  ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -88,6 +88,8 @@ pdfminer (carnil)
 --
 php-laravel-framework/oldstable
 --
+postorius (jmm)
+--
 pyjwt (jmm)
   Jochen Sprickerhof posted debdiffs for review
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a19c2c9b8b3a7632ef32d5da02ea7fa2c07258f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a19c2c9b8b3a7632ef32d5da02ea7fa2c07258f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260507/cc9fcf8c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list