ELA-1839-1 python3.7 security update

multiple vulnerabilities

2026-09-30
Packagepython3.7
Version3.7.3-2+deb10u12 (buster)
Related CVEs CVE-2021-23336 CVE-2021-28861 CVE-2022-0391 CVE-2023-24329 CVE-2025-0938 CVE-2025-13462 CVE-2026-0672 CVE-2026-0865 CVE-2026-3644 CVE-2026-4224 CVE-2026-4519 CVE-2026-6100


Multiple Vulnerabilities were found in python3.7, an interactive high-level object-oriented language.

CVE-2021-23336

The Python3.7 vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl
and urllib.parse.parse_qs by using a vector called parameter cloaking. When
the attacker can separate query parameters using a semicolon (;), they can
cause a difference in the interpretation of the request between the proxy
(running with default configuration) and the server. This can result in malicious
requests being cached as completely safe ones, as the proxy would usually not
see the semicolon as a separator, and therefore would not include it in a cache
key of an unkeyed parameter.

**Attention, API-change!**
Please be sure your software is working properly if it uses `urllib.parse.parse_qs`
or `urllib.parse.parse_qsl`, `cgi.parse` or `cgi.parse_multipart`.

Earlier Python versions allowed using both  ``;`` and ``&`` as query parameter
separators in `urllib.parse.parse_qs` and `urllib.parse.parse_qsl`.
Due to security concerns, and to conform with
newer W3C recommendations, this has been changed to allow only a single
separator key, with ``&`` as the default.  This change also affects
`cgi.parse` and `cgi.parse_multipart` as they use the affected
functions internally. For more details, please see their respective
documentation.

CVE-2021-28861

Open redirection vulnerability in http.server

CVE-2022-0391

Functions in the urllib.parse module did not sanitize URLs to remove
newline characters, which could lead to injection attacks.

CVE-2023-24329

Strip C0 control and space chars in urlsplit

CVE-2025-0938

Functions in the urllib.parse and urlparse modules accepted domain
names containing square brackets, which isn't valid.  These
delimiters are only permitted for IPv6 and IPvFuture hosts.  This
problem could result in differential parsing between the Python URL
parser and other specification-compliant URL parsers.

CVE-2025-13462

The "tarfile" module would still apply normalization of AREGTYPE
(\x00) blocks to DIRTYPE, even while processing a multi-block member
such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a
crafted tar archive being misinterpreted by the tarfile module
compared to other implementations.

CVE-2026-0672

When using http.cookies.Morsel, user-controlled cookie values and
parameters can allow injecting HTTP headers into messages. Patch
rejects all control characters within cookie names, values, and
parameters.

CVE-2026-0865

wsgiref.headers.Headers did not reject control characters in
user-controlled header names and values, allowing injection of
additional HTTP headers. Control characters are now rejected.

CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in
http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator,
and unpickling paths were not patched, allowing control characters to
bypass input validation. Additionally, BaseCookie.js_output() lacked
the output validation applied to BaseCookie.output().

CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an
inline document type definition containing a deeply nested content
model a C stack overflow occurs.

CVE-2026-4519

The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize
URLs prior to passing to webbrowser.open().

CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor` and
`bz2.BZ2Decompressor` when a memory allocation fails with a
`MemoryError` and the decompression instance is re-used. This
scenario can be triggered if the process is under memory pressure.
The vulnerability is only present if the program re-uses
decompressor instances across multiple decompression calls even
after a `MemoryError` is raised during decompression. Using the
helper functions to one-shot decompress data such as
`lzma.decompress()` and `bz2.decompress()` are not affected as a new
decompressor instance is used per call. If the decompressor instance
is not re-used after an error condition, this usage is similarly not
vulnerable.


For Debian 10 buster, these problems have been fixed in version 3.7.3-2+deb10u12.

We recommend that you upgrade your python3.7 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.