- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Christopher Obbard
- Date:
- 2026-07-14 18:53:05 UTC
- Severity:
- normal
- Tags:
[ Reason ] This update fixes a minor security issue in Flask where request context handling did not correctly track session access in some cases. The fix is a targeted backport of the upstream security patch: https://github.com/pallets/flask/commit/c17f379390731543eea33a570a47bd4ef76a54fa This fixes CVE-2026-27205. This issue affects the version currently in trixie. The proposed update backports the upstream fix with no unrelated changes. [ Impact ] If the update is not approved users of Flask in trixie remain affected by the security issue. Applications relying on Flask session handling may continue to have incorrect request/session access tracking behaviour. [ Tests ] The patch includes the corresponding upstream test coverage for the changed behaviour. The package builds successfully with the patch applied and the relevant test suite is ran during package build. Also I manually verified the patch behaviour. [ Risks ] The risk is low - the change is a targeted backport from upstream and is limited to request/session context tracking. The patch is small, includes regression test coverage and does not introduce new dependencies or packaging changes. The affected code is central Flask request-context handling so there is some theoretical regression risk for applications using sessions but the patch matches the upstream fix and is limited in scope. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] The update backports the upstream fix for request context session-access tracking. Packaging changes: - Add a Debian patch backporting the upstream fix. - Add the corresponding changelog entry for 3.1.1-1+deb13u1. [ Other info ] n/a
Hi, Please go ahead. Thanks,
package release.debian.org tags 1141544 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: flask Version: 3.1.1-1+deb13u1 Explanation: ensure Vary: Cookie is set on session access [CVE-2026-27205]
package release.debian.org tags 1141544 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: flask Version: 3.1.1-1+deb13u1 Explanation: ensure Vary: Cookie is set on session access [CVE-2026-27205]