Release date:
2026-09-15 13:29:09 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output()
- debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch:
percent-encode the cookie value with urllib.parse.quote() and wrap it in
decodeURIComponent() instead of escaping only the double quote, so a value
containing cannot break out of the script context (CWE-1336).
- CVE-2026-6019
Updated packages:
-
alt-python312_3.12.14-6_amd64.deb
sha:da122aa1e5fd540be0e7327c400561725a778f95
-
alt-python312-debug_3.12.14-6_amd64.deb
sha:f0472603492052028e436ccece0e993119117084
-
alt-python312-devel_3.12.14-6_amd64.deb
sha:1e031b56982d616dd237f660ca34c0fda5177c64
-
alt-python312-idle_3.12.14-6_amd64.deb
sha:8a915e3a9ec87c3a37a32f8eed0a898ea2cf98e7
-
alt-python312-libs_3.12.14-6_amd64.deb
sha:9e4e8b56952ed14f40c7e5b80b3a0b702642646d
-
alt-python312-test_3.12.14-6_amd64.deb
sha:4f0c88d9141b66b80662adcdd1a21e0f7074cc99
-
alt-python312-tkinter_3.12.14-6_amd64.deb
sha:e3f8a7ef4918cf384bf008464bc4623fd68b50e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.