Fedora has issued an advisory today (January 24): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BQTD43DKM4POZPUGIIHMGFJGZHCTEI5F/ The issue is fixed in 0.18.2.
URL: (none) => https://lwn.net/Vulnerabilities/712494/
freeze push for update to 0.18.2 asked
Thanks Philippe. fedmsg-0.18.2-1.mag6 has been uploaded.
Status: NEW => RESOLVEDResolution: (none) => FIXED