Bug 2467797 (CVE-2026-44742)

Summary: CVE-2026-44742 Postorius: Postorius: Cross-Site Scripting via unescaped HTML in message subject
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Postorius. This vulnerability allows an attacker to embed malicious code within the subject of an email message. When an administrator or user views the 'Held messages pop-up', this malicious code is executed in their web browser. This can lead to Cross-Site Scripting (XSS), potentially resulting in unauthorized access to sensitive information or the ability to perform actions on behalf of the user.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2476456, 2476457    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-07 19:01:36 UTC
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.