Junglewise Threat Intelligence

CVE-2026-44742: GNU Mailman Postorius XSS in Held messages pop-up

CVE-2026-44742 · Severity: high · CVSS 7.2 · Published 2026-05-07

Vendors: PyPI.

Executive brief

Postorius, the web interface for the GNU Mailman 3 mailing list manager, contains a security flaw in how it handles email subjects. An attacker can send a specially crafted email that, when viewed by a mailing list administrator in the 'Held messages' area, executes malicious code in their browser. This could allow an attacker to perform administrative actions or steal sensitive session information, and there are reports of this being used in active attacks.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Postorius through version 1.3.13. The flaw is located in 'held_messages.js', where the application uses the jQuery '.html()' method instead of '.text()' to render the 'data.subject' field in the 'Held messages' pop-up. An unauthenticated remote attacker can exploit this by sending an email with a malicious HTML/JavaScript payload in the Subject header. When a list moderator views the held message queue, the payload executes in the context of their session. Although a fix was merged into the master branch in January 2025, it was not immediately included in a formal release, leading to active exploitation in the wild.

Affected products

  • GNU Mailman Postorius through 1.3.13

Timeline

  • 2025-01-19: other: Merge request for fix submitted
  • 2025-01-29: patched: Fix merged into master branch
  • 2026-05-07: advisory: Public disclosure on oss-security mailing list
  • 2026-05-07: disclosed: CVE published
  • 2026-05-01: exploited: Reported active exploitation in the wild

References

Related threats