High severity7.2NVD Advisory· Published May 7, 2026· Updated May 14, 2026
CVE-2026-44742
CVE-2026-44742
Description
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
postoriusPyPI | <= 1.3.13 | — |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868bnvdPatchWEB
- www.openwall.com/lists/oss-security/2026/05/07/3nvdMailing ListPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r7c9-7pjq-hmm8ghsaADVISORY
- gitlab.com/mailman/postorius/-/issues/620nvdVendor AdvisoryIssue TrackingWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44742ghsaADVISORY
News mentions
0No linked articles in our index yet.