[Git][security-tracker-team/security-tracker][master] new python-hpack issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 13:13:12 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f63444e2 by Moritz Muehlenhoff at 2026-09-24T14:12:23+02:00
new python-hpack issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -870,7 +870,9 @@ CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper valid
 CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods ...)
 	TODO: check
 CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, ...)
-	TODO: check
+	- python-hpack <unfixed>
+	NOTE: https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
+	NOTE: https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c (v4.2.0)
 CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
 	TODO: check
 CVE-2026-57854



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f63444e23051b5723d3238a6295a2f695f513ac9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f63444e23051b5723d3238a6295a2f695f513ac9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/37a016c1/attachment.htm>


More information about the debian-security-tracker-commits mailing list