Debian Package Tracker
Register | Log in
Subscribe

restrictedpython

Restricted execution environment for Python 3

Choose email to subscribe with

general
  • source: restrictedpython (main)
  • version: 8.4-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Diwa Tomy [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.0~b3-2
  • oldstable: 4.0~b3-3
  • stable: 8.0-1
  • testing: 8.4-1
  • unstable: 8.4-1
versioned links
  • 4.0~b3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.0~b3-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-restrictedpython
action needed
A new upstream version is available: 8.5 high
A new upstream version 8.5 is available, you should consider packaging it.
Created: 2026-08-21 Last update: 2026-10-09 08:00
Marked for autoremoval on 12 November due to ipywidgets: #1149422 high
Version 8.4-1 of restrictedpython is marked for autoremoval from testing on Thu 12 Nov 2026. It depends (transitively) on ipywidgets, affected by #1149422. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-10-07 Last update: 2026-10-09 07:33
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-55830: (needs triaging) RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter and bypass the embedding application's access policy. This issue is fixed in version 8.3.
  • CVE-2026-76825: (needs triaging) RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format, get_field, get_value, and vformat performed attribute and item traversal internally without passing through RestrictedPython's safer_getattr protections. Restricted code could use those live object references to reach function globals, builtins, file access, or code execution primitives, affecting confidentiality, integrity, and availability in the host environment. This issue is fixed in version 8.4.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-20 Last update: 2026-10-05 05:00
news
[rss feed]
  • [2026-08-12] restrictedpython 8.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-09] Accepted restrictedpython 8.4-1 (source) into unstable (Emmanuel Arias)
  • [2025-11-09] restrictedpython 8.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-07] Accepted restrictedpython 8.1-1 (source) into unstable (Diwa Tomy) (signed by: Emmanuel Arias)
  • [2025-01-30] restrictedpython 8.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-27] Accepted restrictedpython 8.0-1 (source) into unstable (Colin Watson)
  • [2023-09-10] restrictedpython 6.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-04] Accepted restrictedpython 6.2-1 (source) into unstable (Christoph Berg)
  • [2023-09-02] restrictedpython REMOVED from testing (Debian testing watch)
  • [2021-12-28] restrictedpython 4.0~b3-3 MIGRATED to testing (Debian testing watch)
  • [2021-12-22] Accepted restrictedpython 4.0~b3-3 (source) into unstable (Christoph Berg)
  • [2018-09-26] restrictedpython 4.0~b3-2 MIGRATED to testing (Debian testing watch)
  • [2018-09-24] Accepted restrictedpython 4.0~b3-2 (source) into unstable (Mattia Rizzolo)
  • [2018-04-22] restrictedpython 4.0~b3-1 MIGRATED to testing (Debian testing watch)
  • [2018-04-16] Accepted restrictedpython 4.0~b3-1 (source) into unstable (Christoph Berg)
  • [2018-02-04] restrictedpython 4.0~b2-1 MIGRATED to testing (Debian testing watch)
  • [2018-01-29] Accepted restrictedpython 4.0~b2-1 (source all) into unstable, unstable (Christoph Berg)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 8.4-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing