From nobody Mon May 4 17:34:13 2026 X-Original-To: python@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4g8TKK3GwHz6bwkd for ; Mon, 04 May 2026 17:34:13 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R13" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4g8TKK20zfz48tx for ; Mon, 04 May 2026 17:34:13 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1777916053; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=amGj4kPYwxlk0Jvz7sA6mvwJQl3wjM3N80WkKN5MIWc=; b=laZRDZ4Nn/pIfxarY9/LTFNt1m7ReFt3sqojmAhD90/XMlZrWa7q4j3tHstXzh/XT3Ef3h ulyn38XKsRKbY8Bmdsm405wJam9XiHvvVXhFeFb4Yr1H4BRYQNFNeESo8O4OMzDm6F3Vq4 lgJzBTLMEWqCBJQLkZnCShr3HUzQjd6fBm3q0GzxxGf3HenNpHoi8sQGoAEyFUUjSVzvSS Q4JNF10Oy3/P6bsWXa5GwDWyUg5HgJ9yRPyHjJ2Jw/SA6rsxKF/ZWAM2rGSHmWruupm0Lx k1Q820YWHEhy4ObQASsifhnYqENfR7deQLBWlqDXOafSa6HJpdLVMHQDmdnvxQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1777916053; a=rsa-sha256; cv=none; b=gUCsJHhiCHDeQcNI7oIiEV0J1r09bi3QbE/vWiRpthIbG6OXri7QYZDYLxKlh6Y4FIDjLf bUbu2dlFxgN/jf68xYui9Ca26Z/rMRIY+fWIIR/+k+nv8k7ymyZ0L1KvIGtJWoVbgaGSCZ qLv9Uik27w6bMjwP16wq6hEsS+YkZfopgiz/UgjRvGuD1Ika/9HR440begXHB/XBKMLGld lP2rHOE71h0ImyV2Mv3isyLY9LfdNtOoHx2WqkTePuwJqtq64kNZK9brc9Dw0uzGFQqdIY 9SWdPFn+gyqQ8GtXOV4igI4aaQiUNO4TnHMLLII7UvcDn4TELRWfhQr1P3j8Kg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1777916053; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=amGj4kPYwxlk0Jvz7sA6mvwJQl3wjM3N80WkKN5MIWc=; b=g/i0MDDOOft2Jdblm84fCSmOYqy9FDF2FtG7/KRLnP/L3ns4vc2c11tSHVfd3Ms/V7PVVM bEc1T2ora7yvX4Nbf5MMXX/2GRfFqo4DbpOag4wJQHJziBoHArPChy/7C9D8/hsbp13VhX wz9uveft4s+ZQOvwJ3xjg1352I2RdxGTucl5UOComVjoXoarOaCcgidjmTg9asuPlOW8nS HOHjcM4cwNsJ/1fKwzP6/MxjsQnlhTTZ2EmEWzXJvUrJHxjG9HAVCZ6K9ghREwiC/ndxD2 QMXEhkPIoIHUrh6W9zJ5eZA6kDRbwzib58Js9xYFcoZapsOeawz+gVDZqYzTrQ== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4g8TKK1cPLzVWt for ; Mon, 04 May 2026 17:34:13 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 644HYDKo082965 for ; Mon, 4 May 2026 17:34:13 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 644HYDID082964 for python@FreeBSD.org; Mon, 4 May 2026 17:34:13 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: python@FreeBSD.org Subject: [Bug 294496] lang/python*: CVE-2026-4786: webbrowser.open() command injection mitigation for CVE-2026-4519 was incomplete Date: Mon, 04 May 2026 17:34:13 +0000 X-Bugzilla-Reason: CC X-Bugzilla-Type: dep_changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Ports & Packages X-Bugzilla-Component: Individual Port(s) X-Bugzilla-Version: Latest X-Bugzilla-Keywords: security X-Bugzilla-Severity: Affects Many People X-Bugzilla-Who: joneum@FreeBSD.org X-Bugzilla-Status: Open X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: ports-secteam@FreeBSD.org X-Bugzilla-Flags: maintainer-feedback+ merge-quarterly? X-Bugzilla-Changed-Fields: bug_status resolution Message-ID: In-Reply-To: References: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: FreeBSD-specific Python issues List-Archive: https://lists.freebsd.org/archives/freebsd-python List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-python@freebsd.org Sender: owner-freebsd-python@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D294496 Bug 294496 depends on bug 294486, which changed state. Bug 294486 Summary: lang/python314: needs fix for CVE-2026-6100 use-after-f= ree in decompressors when reusing instances after MemoryError https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D294486 What |Removed |Added ---------------------------------------------------------------------------- Status|Open |Closed Resolution|--- |FIXED --=20 You are receiving this mail because: You are on the CC list for the bug.=