{"id":"CVE-2026-44742","details":"Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.","aliases":["GHSA-r7c9-7pjq-hmm8","PYSEC-2026-2891"],"modified":"2026-07-15T01:49:06.380114734Z","published":"2026-05-07T18:09:20.069Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44742.json","cna_assigner":"mitre","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/05/msg00045.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/05/07/3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44742.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44742"},{"type":"REPORT","url":"https://gitlab.com/mailman/postorius/-/issues/620"},{"type":"FIX","url":"https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b"},{"type":"FIX","url":"https://gitlab.com/mailman/postorius/-/merge_requests/972"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/mailman/postorius","events":[{"introduced":"0"},{"fixed":"c4706abd05ba6bcf472fc674b160d3a9d6a4868b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.3.13"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:*"}}],"versions":["v1.3.13","v1.3.13a1","v1.3.12","v1.3.11","v1.3.10","v1.3.9","1.3.8","1.3.7","1.3.6","1.3.6b1","1.3.4","1.3.4rc1","1.3.3","1.3.3rc2","1.3.3rc1","1.3.2","1.3.1","1.3.0","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.1.2","1.1.0","1.0.2","1.0.1","1.0.0","1.0.0b2","1.0.0b1","postorius-1.0.0a-pypi","postorius-1.0.0a1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44742.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}