Version 1.3.13-3 of postorius is marked for autoremoval from testing on Thu 12 Nov 2026. It depends (transitively) on ipywidgets, affected by #1149422. You should try to prevent the removal by fixing these RC bugs.
CVE-2026-44742:
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
CVE-2026-44742:
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Among the 5 debian patches
available in version 1.3.13-3 of the package,
we noticed the following issues:
4 patches
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.