CVE-2026-44742
בינונית 6.1
תיאור (מקור, אנגלית)
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/8/2026
- CWE
- CWE-79
מוצרים מושפעים
postorius_project: postorius
קישורים
- https://gitlab.com/mailman/postorius/-/issues/620 Issue TrackingVendor Advisory
- https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9… Patch
- https://gitlab.com/mailman/postorius/-/merge_requests/972 Issue TrackingPatch
- https://www.openwall.com/lists/oss-security/2026/05/07/3 Mailing ListPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2026/05/msg00045.html