[CLSA-2026:1785168309] alt-python310-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 16:05:24 UTC
Description:
- CVE-2023-5752: Mercurial revision option injection in pip VCS URLs - CVE-2025-8869: symlink target not validated in tar extraction fallback - CVE-2026-1703: path traversal via os.path.commonprefix in is_within_directory - CVE-2026-3219: tar/ZIP polyglot archive type confusion in unpack_file - CVE-2026-6357: pip self-version check runs after install allowing module shadowing
Updated packages:
  • alt-python310-pip-21.3.1-6.el8.noarch.rpm
    sha:60aca15c67f8018893534659acec2317bff68c437895040128dc37441870dbd0
  • alt-python310-pip-wheel-21.3.1-6.el8.noarch.rpm
    sha:8684971bc289f56fa6642d81d9ca9cf779e389d3a3d43f0a027352ef3f399374
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.