CVE-2019-25026: Debian Linux

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Redmine Redmine: before 3.4.13 (fixed in 3.4.13); from 4.0.0, before 4.0.6 (fixed in 4.0.6)

Published 2021-04-06. Last modified 2026-06-17.