[Git][security-tracker-team/security-tracker][master] pyrhon3.14 fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 5 11:59:07 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7d0e9503 by Moritz Muehlenhoff at 2026-09-05T12:58:14+02:00
pyrhon3.14 fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12332,7 +12332,7 @@ CVE-2026-16231 (hbs is an Express view engine that wraps Handlebars. Its registe
 	NOT-FOR-US: express-hbs
 CVE-2026-15310 (When decompressing crafted zip files using the bzip/LZMA/Zstandard   c ...)
 	- python3.15 3.15.0~rc2-1
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-3
 	- python3.13 <unfixed>
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -12342,6 +12342,7 @@ CVE-2026-15310 (When decompressing crafted zip files using the bzip/LZMA/Zstanda
 	NOTE: https://github.com/python/cpython/pull/156003
 	NOTE: https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4 (main)
 	NOTE: https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8 (v3.15.0rc2)
+	NOTE: https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89 (3.14)
 CVE-2026-13478 (The Zephyr ext2 filesystem driver validates the on-disk block bitmap i ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13217 (The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a sessi ...)
@@ -17484,7 +17485,7 @@ CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attac
 	NOT-FOR-US: IBM
 CVE-2026-19672 (The tarfile module's tar and data  extraction filters created director ...)
 	- python3.15 3.15.0~rc2-1
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-3
 	- python3.13 <unfixed>
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -20994,7 +20995,7 @@ CVE-2026-17106 (The tar extraction routines in moby/go-archive (Unpack, UnpackLa
 	NOTE: https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
 CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454 tables ...)
 	- python3.15 3.15.0~rc2-1
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-3
 	- python3.13 <unfixed>
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
@@ -21009,11 +21010,12 @@ CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454
 	NOTE: https://github.com/python/cpython/pull/155293
 	NOTE: Fixed by: https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc (main)
 	NOTE: Fixed by: https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7 (v3.15.0rc2)
+	NOTE: Fixed by: https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae (3.14)
 CVE-2026-16309 (Authorization bypass through User-Controlled key vulnerability in Neti ...)
 	NOT-FOR-US: EdoWEB
 CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along with its ...)
 	- python3.15 3.15.0~rc2-1
-	- python3.14 <unfixed>
+	- python3.14 3.14.7-3
 	- python3.13 <unfixed>
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d0e9503948329e2f81e7cd91e54eb263d131e17

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d0e9503948329e2f81e7cd91e54eb263d131e17
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/86e73a5c/attachment.htm>


More information about the debian-security-tracker-commits mailing list