Release date:
2026-09-15 13:45:51 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output()
- debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch:
percent-encode the cookie value with urllib.parse.quote() and wrap it in
decodeURIComponent() instead of escaping only the double quote, so a value
containing cannot break out of the script context (CWE-1336).
- CVE-2026-6019
Updated packages:
-
alt-python312_3.12.14-6_amd64.deb
sha:a8c3cf8fbbcb50d478682fb1f1a64e2eb5225c4a
-
alt-python312-debug_3.12.14-6_amd64.deb
sha:f0472603492052028e436ccece0e993119117084
-
alt-python312-devel_3.12.14-6_amd64.deb
sha:38e1764961c9ebff5a33c5a236736b8dee3443df
-
alt-python312-idle_3.12.14-6_amd64.deb
sha:1c988872f348c064d86db294b62bf63c2062679d
-
alt-python312-libs_3.12.14-6_amd64.deb
sha:00d36e6dfbdee8a72ac29e9a2db70b5beed32967
-
alt-python312-test_3.12.14-6_amd64.deb
sha:2d0726538b8c5122311c257f92d949e0d95956c4
-
alt-python312-tkinter_3.12.14-6_amd64.deb
sha:bfa9338b5903399ae704dbee00a2f1925be48165
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.