mailman
Mailman -- the GNU mailing list manager
Activity
- Latest release
- 1y ago
- Total releases
- 51
- Cadence
- ~3 months
- Last 12 months
- 0
Details
- License
- GPL-3.0
- First release
- Apr 09, 2008
| Version | Released | |
|---|---|---|
3.3.10
patch
|
3.3.10
patch
Dependencies (23)
+ 15 more |
|
3.3.10b2
pre
|
3.3.10b2
pre
Dependencies (23)
+ 15 more |
|
3.3.10b1
pre
|
3.3.10b1
pre
Dependencies (23)
+ 15 more |
|
3.3.9
patch
|
3.3.9
patch
|
|
3.3.8
patch
|
3.3.8
patch
|
|
3.3.7
patch
|
3.3.7
patch
|
|
3.3.6
patch
|
3.3.6
patch
|
|
3.3.5
patch
|
3.3.5
patch
|
|
3.3.5rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.5rc1
pre
|
|
3.3.5b1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.5b1
pre
|
|
3.3.4
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.4
patch
|
|
3.3.3
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.3
patch
|
|
3.3.3rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.3rc1
pre
|
|
3.3.2
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.2
patch
|
|
3.3.2rc2
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.2rc2
pre
|
|
3.3.2rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.2rc1
pre
|
|
3.3.1
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.1
patch
Dependencies (22)
+ 14 more |
|
3.3.1rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.1rc1
pre
Dependencies (22)
+ 14 more |
|
3.3.0
minor
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (22)
+ 14 more |
|
3.2.2
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.2.2
patch
|
|
3.2.1
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.2.1
patch
|
|
3.2.1rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.2.1rc1
pre
|
|
3.2.0
minor
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.2.0
minor
|
|
3.1.1
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.1
patch
|
|
3.1.0
minor
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0
minor
|
|
3.1.0rc2
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0rc2
pre
|
|
3.1.0rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0rc1
pre
|
|
3.1.0b5
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0b5
pre
|
|
3.1.0b4
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0b4
pre
|
|
3.1.0b3
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0b3
pre
|
|
3.1.0b2
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0b2
pre
|
|
3.1.0b1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.1.0b1
pre
|
|
3.0.3
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.3
patch
|
|
3.0.2
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.2
patch
|
|
3.0.1
patch
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.1
patch
|
|
3.0.0
initial
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0
initial
|
|
3.0rc1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0rc1
pre
|
|
3.0.0b5
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0b5
pre
|
|
3.0.0b4
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0b4
pre
|
|
3.0.0b3-
pre
6 CVEs
CVE-2004-1177
PYSEC-2026-659
GHSA-rh6c-jh4c-9fg3
Jul 02, 2026
mailman Cross-site scripting (XSS) vulnerability Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page. Affected versions
3.0.0b3-
Fixed in
2.1.5
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2004-0412
PYSEC-2026-658
GHSA-hj4h-vqpq-95wg
Jul 02, 2026
Mailman Sensitive Information Disclosure Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server. Affected versions
3.0.0b3-
Fixed in
2.1.5
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2003-0038
PYSEC-2026-657
GHSA-82rm-28q9-435p
Jul 02, 2026
Mailman Cross-site scripting (XSS) vulnerability Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters. Affected versions
3.0.0b3-
Fixed in
2.1.1
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-44227
PYSEC-2026-660
GHSA-xq58-69h2-765m
Jul 02, 2026
Cross Site Request Forgery in mailman
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes. Affected versions
3.0.0b3-
Fixed in
2.1.38
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2018-13796
PYSEC-2026-661
GHSA-xqvg-xm9m-p2c4
Jul 02, 2026
Moderate severity vulnerability that affects mailman
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site. Affected versions
3.0.0b3-
Fixed in
2.1.28
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0b3-
pre
|
|
3.0.0b3
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0b3
pre
|
|
3.0.0b2
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0b2
pre
|
|
3.0.0b1
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0b1
pre
|
|
3.0.0a8
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a8
pre
|
|
3.0.0a7
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a7
pre
|
|
3.0.0a6
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a6
pre
|
|
3.0.0a5
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a5
pre
|
|
3.0.0a4
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a4
pre
|
|
3.0.0a3
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a3
pre
|
|
3.0.0a2
pre
1 CVE
CVE-2021-34337
GHSA-2jg5-xgvv-4wq7
PYSEC-2023-22
Apr 15, 2023
Mailman Core vulnerable to timing attacks
High
Network
Low
Low
None
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces. Affected versions
3.0.0
3.0.0a1
3.0.0a2
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.0b2
3.0.0b3
+ 31 more Show less
3.0.0b3-
3.0.0b4
3.0.0b5
3.0.1
3.0.2
3.0.3
3.0rc1
3.1.0
3.1.0b1
3.1.0b2
3.1.0b3
3.1.0b4
3.1.0b5
3.1.0rc1
3.1.0rc2
3.1.1
3.2.0
3.2.1
3.2.1rc1
3.2.2
3.3.0
3.3.1
3.3.1rc1
3.3.2
3.3.2rc1
3.3.2rc2
3.3.3
3.3.3rc1
3.3.4
3.3.5b1
3.3.5rc1
Fixed in
3.3.5
References
Updated Feb 22, 2026 · Source: OSV.dev |
3.0.0a2
pre
|