[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-7210/py*: reference libexpat pre-req CVE
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Mon May 18 11:47:28 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a966cd4f by Sylvain Beucler at 2026-05-18T12:47:17+02:00
CVE-2026-7210/py*: reference libexpat pre-req CVE
- - - - -
2d30cec1 by Sylvain Beucler at 2026-05-18T12:47:20+02:00
CVE-2025-69534,CVE-2026-1502,CVE-2026-6019/python3.9: bullseye postponed
aligning with other dists
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4235,8 +4235,8 @@ CVE-2026-7210 (`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient
NOTE: https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4 (main)
NOTE: https://github.com/python/cpython/pull/149645 (3.15)
NOTE: https://github.com/python/cpython/pull/149646 (3.14)
- NOTE: Fully mitigating this vulnerability requires both updating libexpat to
- NOTE: 2.8.0 or later and applying the python patch for CVE-2026-7210.
+ NOTE: Fully mitigating this vulnerability requires fixing both libexpat
+ NOTE: (CVE-2026-41080) and applying the python patch for CVE-2026-7210.
CVE-2026-6956 (ATutor is vulnerable to Reflected XSS in/install/install.php endpoint. ...)
NOT-FOR-US: ATutor
CVE-2026-6909 (ATutor is vulnerable to Reflected XSS in/install/upgrade.php endpoint. ...)
@@ -15417,6 +15417,7 @@ CVE-2026-6019 (http.cookies.Morsel.js_output() returns an inline <script> snippe
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
+ [bullseye] - python3.9 <postponed> (Minor issue, unused function)
- pypy3 <unfixed> (bug #1135116)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <no-dsa> (Minor issue)
@@ -21989,6 +21990,7 @@ CVE-2026-1502 (CR/LF bytes were not rejected by HTTP client proxy tunnel headers
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
+ [bullseye] - python3.9 <no-dsa> (Minor issue, response splitting)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 7.3.22+dfsg-1
@@ -42103,6 +42105,7 @@ CVE-2025-69534 (Python-Markdown version 3.8 contain a vulnerability where malfor
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
+ [bullseye] - python3.9 <postponed> (Minor issue, DoS)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d4c43ab1edaa59bb37770c3d0e0202b39e939fee...2d30cec1cd6b25c56036753e4274271c0acd388a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d4c43ab1edaa59bb37770c3d0e0202b39e939fee...2d30cec1cd6b25c56036753e4274271c0acd388a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260518/5d5da397/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list