[CLSA-2026:1789479939] Fix CVE(s): CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-15 13:45:51 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output() - debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch: percent-encode the cookie value with urllib.parse.quote() and wrap it in decodeURIComponent() instead of escaping only the double quote, so a value containing cannot break out of the script context (CWE-1336). - CVE-2026-6019
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-6_amd64.deb
    sha:a8c3cf8fbbcb50d478682fb1f1a64e2eb5225c4a
  • alt-python312-debug_3.12.14-6_amd64.deb
    sha:f0472603492052028e436ccece0e993119117084
  • alt-python312-devel_3.12.14-6_amd64.deb
    sha:38e1764961c9ebff5a33c5a236736b8dee3443df
  • alt-python312-idle_3.12.14-6_amd64.deb
    sha:1c988872f348c064d86db294b62bf63c2062679d
  • alt-python312-libs_3.12.14-6_amd64.deb
    sha:00d36e6dfbdee8a72ac29e9a2db70b5beed32967
  • alt-python312-test_3.12.14-6_amd64.deb
    sha:2d0726538b8c5122311c257f92d949e0d95956c4
  • alt-python312-tkinter_3.12.14-6_amd64.deb
    sha:bfa9338b5903399ae704dbee00a2f1925be48165
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.