Skip to content

PYSEC-2022-236/PYSEC-2022-42972/PYSEC-2023-72: Fix conflicting introduced/fixed events#255

Merged
westonsteimel merged 3 commits into
pypa:mainfrom
progval:conflicting-fixed-introduced
Jun 8, 2026
Merged

PYSEC-2022-236/PYSEC-2022-42972/PYSEC-2023-72: Fix conflicting introduced/fixed events#255
westonsteimel merged 3 commits into
pypa:mainfrom
progval:conflicting-fixed-introduced

Conversation

@progval

@progval progval commented Jan 16, 2026

Copy link
Copy Markdown
Contributor

eg. for PYSEC-2023-72, version 3.2.0 is said to both fix and introduce the vulnerability.

My guess is this inconsistency comes from https://nvd.nist.gov/vuln/detail/cve-2023-32007 claiming 'up to version 3.1.3' even though this is the last version before version 3.2.0, which is also vulnerable

…roduce and fix it

My guess is this inconsistency comes from https://nvd.nist.gov/vuln/detail/cve-2023-32007 claiming
'up to version 3.1.3' even though this is the last version before version 3.2.0, which is also vulnerable
@westonsteimel westonsteimel merged commit 98a7c69 into pypa:main Jun 8, 2026
1 check passed
@westonsteimel

Copy link
Copy Markdown
Collaborator

Thank you, and apologies for the wait on these

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants