---
id: CVE-2018-13796
aliases:
  - GHSA-xqvg-xm9m-p2c4
  - PYSEC-2026-661
title: Moderate severity vulnerability that affects mailman
summary: Moderate severity vulnerability that affects mailman
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
vendor: mailman
product: mailman
ecosystem: pip
affected:
  - mailman < 2.1.28
patched:
  - mailman 2.1.28
published: '2018-09-11'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-xqvg-xm9m-p2c4'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2018-13796'
  - url: 'https://bugs.launchpad.net/mailman/+bug/1780874'
  - url: 'https://github.com/advisories/GHSA-xqvg-xm9m-p2c4'
  - url: 'https://lists.debian.org/debian-lts-announce/2018/07/msg00034.html'
  - url: 'https://security.gentoo.org/glsa/201904-10'
  - url: 'https://usn.ubuntu.com/4348-1'
  - url: 'https://www.mail-archive.com/mailman-users@python.org/msg71003.html'
tags:
  - osv
  - pip
epss: 0.02705
epssPercentile: 0.85245
ingestedAt: '2026-07-08T18:25:54.653Z'
---

## Overview

An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

## Affected packages

- `mailman < 2.1.28`

## Remediation

Upgrade to a patched release:

- `mailman 2.1.28`
