[Git][security-tracker-team/security-tracker][master] CVE-2026-19672,CVE-2026-87910,CVE-2026-12756/python: affects PEP 706
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Wed Sep 16 10:07:17 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d9da6688 by Sylvain Beucler at 2026-09-16T11:07:10+02:00
CVE-2026-19672,CVE-2026-87910,CVE-2026-12756/python: affects PEP 706
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2182,9 +2182,10 @@ CVE-2026-12756 (IBM Business Automation Workflow containers and traditional is v
CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar extractio ...)
- python3.13 <unfixed>
[trixie] - python3.13 <no-dsa> (Minor issue)
- - python3.11 <removed>
+ - python3.11 <not-affected> (extraction filters (PEP 706) absent in 3.11.2)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
+ [bookworm] - pypy3 <not-affected> (extraction filters (PEP 706) absent in stdlib 3.9.16)
NOTE: https://github.com/python/cpython/issues/157190
NOTE: https://github.com/python/cpython/pull/157191
NOTE: https://github.com/python/cpython/pull/157262 (3.15)
@@ -2193,6 +2194,7 @@ CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar ext
NOTE: https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d (3.13 branch)
NOTE: https://github.com/python/cpython/pull/157454 (3.12)
NOTE: Fixed by changes in Python 3.14, some followup changes for 3.15/3.16, but without security impact
+ NOTE: Same code situation as with CVE-2025-4435.
CVE-2026-9812 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-91081 (Docs through 5.6.1 contains a server-side request forgery vulnerabilit ...)
@@ -5327,13 +5329,15 @@ CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support li
- python3.14 <unfixed>
- python3.13 <unfixed>
[trixie] - python3.13 <no-dsa> (Minor issue)
- - python3.11 <removed>
+ - python3.11 <not-affected> (extraction filters (PEP 706) absent in 3.11.2)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
+ [bookworm] - pypy3 <not-affected> (extraction filters (PEP 706) absent in stdlib 3.9.16)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/
NOTE: https://github.com/python/cpython/issues/157265
NOTE: https://github.com/python/cpython/pull/157266
NOTE: https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2 (main)
+ NOTE: Same code situation as with CVE-2025-4435.
CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
- node-morgan 1.12.1+~1.9.10-1 (bug #1147520)
[trixie] - node-morgan <no-dsa> (Minor issue)
@@ -30210,11 +30214,11 @@ CVE-2026-19672 (The tarfile module's tar and data extraction filters created di
- python3.14 3.14.7-3
- python3.13 <unfixed>
[trixie] - python3.13 <no-dsa> (Minor issue)
- - python3.11 <removed>
- - python3.9 <removed>
+ - python3.11 <not-affected> (extraction filters (PEP 706) absent in 3.11.2)
+ - python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
- [bookworm] - pypy3 <postponed> (Minor issue)
+ [bookworm] - pypy3 <not-affected> (extraction filters (PEP 706) absent in stdlib 3.9.16)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
NOTE: https://github.com/python/cpython/issues/155999
NOTE: https://github.com/python/cpython/pull/156000
@@ -30222,6 +30226,7 @@ CVE-2026-19672 (The tarfile module's tar and data extraction filters created di
NOTE: https://github.com/python/cpython/commit/16dea1e887ec7dfbed735beedd476b21dcc91a79 (3.14 branch)
NOTE: https://github.com/python/cpython/commit/c7979f3a819011a3222bd16e671264b1e34282cb (3.13 branch)
NOTE: https://github.com/python/cpython/commit/a5bfd964c71de4e8dfec59d28060bff1402baa21 (3.12 branch)
+ NOTE: Same code situation as with CVE-2025-4435.
CVE-2026-19653 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
NOT-FOR-US: IBM
CVE-2026-19490 (Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affe ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9da6688c1198168621f391b494a09363689019f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9da6688c1198168621f391b494a09363689019f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/0e7d4b6b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list