Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Commit 9034a44

Browse files
authored
doc(python-3.1[123]): Add pending-upstream-fix CVE-2025-13836 (#27768)
python-3.11 Upstream Fix PR: python/cpython#142141 python-3.12 Upstream Fix PR: python/cpython#142140 python-3.13 Upstream Fix PR: python/cpython#142139 python-3.13 Local Fix PR: wolfi-dev/os#75166 Signed-off-by: Vivian Rook <vivian.rook@chainguard.dev>
1 parent bd03634 commit 9034a44

3 files changed

Lines changed: 12 additions & 0 deletions

File tree

python-3.11.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -423,6 +423,10 @@ advisories:
423423
componentType: apk
424424
componentLocation: /.PKGINFO
425425
scanner: grype
426+
- timestamp: 2025-12-08T15:06:57Z
427+
type: pending-upstream-fix
428+
data:
429+
note: 'Upstream are actively working on, and have a PR open regarding this issue. Upstream maintainers will need to approve and merge the PR. Fix PR: https://github.com/python/cpython/pull/142141'
426430

427431
- id: CGA-v7vq-q3hm-p8cq
428432
aliases:

python-3.12.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -451,6 +451,10 @@ advisories:
451451
componentType: apk
452452
componentLocation: /.PKGINFO
453453
scanner: grype
454+
- timestamp: 2025-12-08T15:07:39Z
455+
type: pending-upstream-fix
456+
data:
457+
note: 'Upstream are actively working on, and have a PR open regarding this issue. Upstream maintainers will need to approve and merge the PR. Fix PR: https://github.com/python/cpython/pull/142140'
454458

455459
- id: CGA-w8x7-4w8c-66cp
456460
aliases:

python-3.13.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -222,6 +222,10 @@ advisories:
222222
componentType: apk
223223
componentLocation: /.PKGINFO
224224
scanner: grype
225+
- timestamp: 2025-12-08T15:19:19Z
226+
type: pending-upstream-fix
227+
data:
228+
note: 'Upstream has patched this, but has yet to release a new point version including the patch. Awaiting new release. Patch PR: https://github.com/python/cpython/pull/142139 We have included the patch locally in: https://github.com/wolfi-dev/os/pull/75166'
225229

226230
- id: CGA-gf9w-x54c-mr2x
227231
aliases:

0 commit comments

Comments
 (0)