[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-7210/py*: reference libexpat pre-req CVE

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Mon May 18 11:47:28 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a966cd4f by Sylvain Beucler at 2026-05-18T12:47:17+02:00
CVE-2026-7210/py*: reference libexpat pre-req CVE

- - - - -
2d30cec1 by Sylvain Beucler at 2026-05-18T12:47:20+02:00
CVE-2025-69534,CVE-2026-1502,CVE-2026-6019/python3.9: bullseye postponed

aligning with other dists

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4235,8 +4235,8 @@ CVE-2026-7210 (`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient
 	NOTE: https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4 (main)
 	NOTE: https://github.com/python/cpython/pull/149645 (3.15)
 	NOTE: https://github.com/python/cpython/pull/149646 (3.14)
-	NOTE: Fully mitigating this vulnerability requires both updating libexpat to
-	NOTE: 2.8.0 or later and applying the python patch for CVE-2026-7210.
+	NOTE: Fully mitigating this vulnerability requires fixing both libexpat
+	NOTE: (CVE-2026-41080) and applying the python patch for CVE-2026-7210.
 CVE-2026-6956 (ATutor is vulnerable to Reflected XSS in/install/install.php endpoint. ...)
 	NOT-FOR-US: ATutor
 CVE-2026-6909 (ATutor is vulnerable to Reflected XSS in/install/upgrade.php endpoint. ...)
@@ -15417,6 +15417,7 @@ CVE-2026-6019 (http.cookies.Morsel.js_output() returns an inline <script> snippe
 	- python3.11 <removed>
 	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
+	[bullseye] - python3.9 <postponed> (Minor issue, unused function)
 	- pypy3 <unfixed> (bug #1135116)
 	[trixie] - pypy3 <no-dsa> (Minor issue)
 	[bookworm] - pypy3 <no-dsa> (Minor issue)
@@ -21989,6 +21990,7 @@ CVE-2026-1502 (CR/LF bytes were not rejected by HTTP client proxy tunnel headers
 	- python3.11 <removed>
 	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
+	[bullseye] - python3.9 <no-dsa> (Minor issue, response splitting)
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
 	- pypy3 7.3.22+dfsg-1
@@ -42103,6 +42105,7 @@ CVE-2025-69534 (Python-Markdown version 3.8 contain a vulnerability where malfor
 	- python3.11 <removed>
 	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
+	[bullseye] - python3.9 <postponed> (Minor issue, DoS)
 	- pypy3 <unfixed>
 	[trixie] - pypy3 <no-dsa> (Minor issue)
 	[bookworm] - pypy3 <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d4c43ab1edaa59bb37770c3d0e0202b39e939fee...2d30cec1cd6b25c56036753e4274271c0acd388a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d4c43ab1edaa59bb37770c3d0e0202b39e939fee...2d30cec1cd6b25c56036753e4274271c0acd388a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260518/5d5da397/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list