Back Linuxsecurity Fedora 44 python-postorius Critical Cross-Site Scripting CVE-2026
Update to 1.3.13 (minor packaging changes); backport unreleased fix for cross- side scripting via unescaped HTML
* Wed Jun 17 2026 Michel Lind - 1.3.13-1 - Backport unreleased fix for CVE-2026-44742 - With 1.3.13 we no longer need to exclude example_project * Tue Jun 16 2026 Python Maint - 1.3.12-8 - Rebuilt for Python 3.15
* Wed Jun 17 2026 Michel Lind - 1.3.13-1 - Backport unreleased fix for CVE-2026-44742 - With 1.3.13 we no longer need to exclude example_project * Tue Jun 16 2026 Python Maint - 1.3.12-8 - Rebuilt for Python 3.15
[ 1 ] Bug #2476457 - CVE-2026-44742 python-postorius: Postorius: Cross-Site Scripting via unescaped HTML in message subject [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ef34f94241' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
