—
PYSEC-2026-658
Mailman Sensitive Information Disclosure
Quick fix
PYSEC-2026-658 — mailman: upgrade to the fixed version with the command below.
pip install --upgrade 'mailman>=2.1.5'Details
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2004-0412[ADVISORY]
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16256[WEB]
- https://gitlab.com/mailman[WEB]
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842[WEB]
- http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html[WEB]
- http://marc.info/?l=bugtraq&m=109034869927955&w=2[WEB]
- http://secunia.com/advisories/11701[WEB]
- http://security.gentoo.org/glsa/glsa-200406-04.xml[WEB]
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051[WEB]
- http://www.securityfocus.com/bid/10412[WEB]
- https://pypi.org/project/mailman[PACKAGE]
- https://github.com/advisories/GHSA-hj4h-vqpq-95wg[ADVISORY]