Ubuntu alert USN-8323-1 (postorius)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8323-1] Postorius vulnerability | |
| Date: | Wed, 27 May 2026 16:54:52 +0000 | |
| Message-ID: | <E1wSHWu-0001ym-CO@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8323-1 May 27, 2026 postorius vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Postorius could be made to expose sensitive information over the network. Software Description: - postorius: Django based management interface for Mailman Details: It was discovered that Postorius did not properly escape HTML in message subjects when rendering the Held messages pop-up. An attacker could possibly use this issue to inject arbitrary HTML, resulting in exposure of sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-django-postorius 1.3.13-1ubuntu1.1~26.04.1 Ubuntu 25.10 python3-django-postorius 1.3.13-1ubuntu1.1~25.10.1 Ubuntu 24.04 LTS python3-django-postorius 1.3.10-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-django-postorius 1.3.5-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-django-postorius 1.2.4-1ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-django-postorius 1.1.2-3ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8323-1 CVE-2026-44742 Package Information: https://launchpad.net/ubuntu/+source/postorius/1.3.13-1ub... https://launchpad.net/ubuntu/+source/postorius/1.3.13-1ub...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoXINkACgkQcpJm3tlz hgEWSBAAqmXfSwOGuxCq7Ng3XM4ZtQJohPKt6kvW1sC/Tga9bhuV4uuudrNpp8gd wzpozNSopL2Ds8G3nHdAY/ND8Impcm5b6Gyrlr/Zs0zzOYk2ZWTqc1L9oLbQ6Df+ OwD/o/WE3cpi2BtF0IAhwrSULxMjL+MNHjQOhf5FkBnQDTrBUVS0Dmrl5BFeuUKd s+MvMG1w4NgEcuTa4Kz7r/U4NTPaZCexH5Hd++PzHXWm9FTqdVLwkIQAakEcq7q8 tlFVZ3gKcoN1kJLr75KlOjB+eF8yK1sBjwjnXcMZs5F25pkqv3qLKd15lwBoq3Lr nwBFj4ORRc2xp+EBCqm2LVtmNXbHSFXMk6ROQxnrao6IuqcNZFRPbu1Vy2BQFqXZ sDQ2aZFgehyf7lgMnJkVmY4ltIehp2KCUFWXWaOzmnj4CAVNBCApaSRMNdLCOGTX BMSalvVxJj9et9XGLOrtOX0X3544XMUm8KMoJoiUiHx+frbgoVX8aQNAqG3jTFTw VXur+LNZtJGtZe5Pmtpj5fpOaYR10FtDqSJIoxhG1Dm12jx34ODA3pAoCoawxKMP LSVacE51F271qBccfznbnTSC/wARMDw/uEpMCAlM1t2cz9MIFuDmoOUZ0J+yH4Ub O14uHWPIk78Pa2TKX/8tqef2KHth56eRCejTUnxngB/ma96cDCE= =ilmk -----END PGP SIGNATURE-----
