#1141544 trixie-pu: package flask/3.1.1-1+deb13u1

#1141544#5
Date:
2026-07-06 02:02:28 UTC
From:
To:
[ Reason ]
This update fixes a minor security issue in Flask where request context
handling did not correctly track session access in some cases.

The fix is a targeted backport of the upstream security patch:

https://github.com/pallets/flask/commit/c17f379390731543eea33a570a47bd4ef76a54fa

This fixes CVE-2026-27205.

This issue affects the version currently in trixie. The proposed update
backports the upstream fix with no unrelated changes.

[ Impact ]
If the update is not approved users of Flask in trixie remain affected
by the security issue. Applications relying on Flask session handling may
continue to have incorrect request/session access tracking behaviour.

[ Tests ]
The patch includes the corresponding upstream test coverage for the
changed behaviour. The package builds successfully with the patch applied
and the relevant test suite is ran during package build. Also I manually
verified the patch behaviour.

[ Risks ]
The risk is low - the change is a targeted backport from upstream and is
limited to request/session context tracking. The patch is small, includes
regression test coverage and does not introduce new dependencies or
packaging changes.

The affected code is central Flask request-context handling so there is
some theoretical regression risk for applications using sessions but the
patch matches the upstream fix and is limited in scope.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
The update backports the upstream fix for request context session-access
tracking.

Packaging changes:
- Add a Debian patch backporting the upstream fix.
- Add the corresponding changelog entry for 3.1.1-1+deb13u1.

[ Other info ]
n/a

#1141544#12
Date:
2026-07-13 17:38:40 UTC
From:
To:
Hi,

Please go ahead.

Thanks,

#1141544#19
Date:
2026-07-14 18:51:52 UTC
From:
To:
package release.debian.org
tags 1141544 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: flask
Version: 3.1.1-1+deb13u1

Explanation: ensure Vary: Cookie is set on session access [CVE-2026-27205]

#1141544#24
Date:
2026-07-14 18:51:52 UTC
From:
To:
package release.debian.org
tags 1141544 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: flask
Version: 3.1.1-1+deb13u1

Explanation: ensure Vary: Cookie is set on session access [CVE-2026-27205]