[Git][security-tracker-team/security-tracker][master] Add follow-up note for CVE-2026-6019/python3

Arnaud Rebillout (@arnaudr) arnaudr at debian.org
Fri May 15 05:41:18 BST 2026



Arnaud Rebillout pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a47bfab5 by Arnaud Rebillout at 2026-05-15T11:40:55+07:00
Add follow-up note for CVE-2026-6019/python3

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14341,6 +14341,7 @@ CVE-2026-6019 (http.cookies.Morsel.js_output() returns an inline <script> snippe
 	NOTE: Fixed by: https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104 (main branch)
 	NOTE: Fixed by: https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8 (v3.14.5rc1)
 	NOTE: Fixed by: https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c (3.13 branch)
+	NOTE: Follow-up: https://github.com/python/cpython/issues/149144
 CVE-2026-5935 (IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9 ...)
 	NOT-FOR-US: IBM
 CVE-2026-5926 (IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Secur ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a47bfab5438776e4ea1a348e3aadc7563888e684

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a47bfab5438776e4ea1a348e3aadc7563888e684
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260515/f82a6c2a/attachment.htm>


More information about the debian-security-tracker-commits mailing list