High severity7.2NVD Advisory· Published May 7, 2026· Updated May 26, 2026
CVE-2026-44742
CVE-2026-44742
Description
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
postoriusPyPI | <= 1.3.13 | — |
Affected products
3Patches
Vulnerability mechanics
References
7- gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868bnvdPatchWEB
- gitlab.com/mailman/postorius/-/merge_requests/972nvdIssue TrackingPatchWEB
- www.openwall.com/lists/oss-security/2026/05/07/3nvdMailing ListPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r7c9-7pjq-hmm8ghsaADVISORY
- gitlab.com/mailman/postorius/-/issues/620nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44742ghsaADVISORY
- lists.debian.org/debian-lts-announce/2026/05/msg00045.htmlnvd
News mentions
0No linked articles in our index yet.