Release date:
2026-07-29 16:21:38 UTC
Description:
- CVE-2026-0864: normalize CR/CRLF line endings in configparser writes to prevent key/value injection
- CVE-2026-1502: reject CR/LF in http.client proxy CONNECT tunnel host and headers
- CVE-2026-3276: fix O(n^2) canonical ordering in unicodedata.normalize() (DoS on crafted combining sequences)
- CVE-2026-6019: percent-encode cookie values embedded in http.cookies js_output() to prevent script injection (XSS)
- CVE-2026-7774: validate written link target in tarfile data filter to prevent path traversal
- CVE-2026-8328: apply CVE-2021-4189 PASV peer-address check to ftplib.ftpcp() to prevent data-connection SSRF
- CVE-2026-11940: fix symlink escape via tarfile hardlink-extraction fallback (path traversal)
- CVE-2026-11972: make tarfile._Stream.seek() break at EOF to prevent infinite-loop DoS on crafted stream archives
Updated packages:
-
alt-python311-3.11.15-5.el9.x86_64.rpm
sha:69efb0147fb9ffa7999a57b797d0d11b6405f7a51a03adc1a792c44fc05ba245
-
alt-python311-debug-3.11.15-5.el9.x86_64.rpm
sha:91f1d2ac96d27ca4a867f315823dc86f66c80b7c94345739a400fc6071d2f99c
-
alt-python311-devel-3.11.15-5.el9.x86_64.rpm
sha:6abdf05bc5dda240224752ef513d7a9872810d1f128929678f6128a382c958f4
-
alt-python311-idle-3.11.15-5.el9.x86_64.rpm
sha:bb7d0a8c9d976f638ee618036670f0754248cd58e914b0291006d75f502ee564
-
alt-python311-libs-3.11.15-5.el9.x86_64.rpm
sha:feee6a41ff7e684ff047d6035348a20c01ee54a2a8b2960acae3070361285703
-
alt-python311-test-3.11.15-5.el9.x86_64.rpm
sha:9f2db43645cf51c3003a8ea5a7ad04d6e881c8615aa7745c85446f424340413d
-
alt-python311-tkinter-3.11.15-5.el9.x86_64.rpm
sha:4c984a6870fe3e4d64e4f51fc2a2ea54d09fb87149cd2c09357975232646476d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.