[CLSA-2026:1789478938] Fix CVE(s): CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-15 13:29:09 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output() - debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch: percent-encode the cookie value with urllib.parse.quote() and wrap it in decodeURIComponent() instead of escaping only the double quote, so a value containing cannot break out of the script context (CWE-1336). - CVE-2026-6019
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-6_amd64.deb
    sha:da122aa1e5fd540be0e7327c400561725a778f95
  • alt-python312-debug_3.12.14-6_amd64.deb
    sha:f0472603492052028e436ccece0e993119117084
  • alt-python312-devel_3.12.14-6_amd64.deb
    sha:1e031b56982d616dd237f660ca34c0fda5177c64
  • alt-python312-idle_3.12.14-6_amd64.deb
    sha:8a915e3a9ec87c3a37a32f8eed0a898ea2cf98e7
  • alt-python312-libs_3.12.14-6_amd64.deb
    sha:9e4e8b56952ed14f40c7e5b80b3a0b702642646d
  • alt-python312-test_3.12.14-6_amd64.deb
    sha:4f0c88d9141b66b80662adcdd1a21e0f7074cc99
  • alt-python312-tkinter_3.12.14-6_amd64.deb
    sha:e3f8a7ef4918cf384bf008464bc4623fd68b50e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.