[CLSA-2026:1785165619] Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 15:24:56 UTC
Description:
* SECURITY UPDATE: Mercurial revision option injection in pip VCS URLs - debian/patches/CVE-2023-5752.patch: Mercurial revision option injection in pip VCS URLs - CVE-2023-5752 * SECURITY UPDATE: symlink target not validated in tar extraction fallback - debian/patches/CVE-2025-8869.patch: symlink target not validated in tar extraction fallback - CVE-2025-8869 * SECURITY UPDATE: path traversal via os.path.commonprefix in is_within_directory - debian/patches/CVE-2026-1703.patch: path traversal via os.path.commonprefix in is_within_directory - CVE-2026-1703 * SECURITY UPDATE: tar/ZIP polyglot archive type confusion in unpack_file - debian/patches/CVE-2026-3219.patch: tar/ZIP polyglot archive type confusion in unpack_file - CVE-2026-3219 * SECURITY UPDATE: pip self-version check runs after install allowing module shadowing - debian/patches/CVE-2026-6357.patch: pip self-version check runs after install allowing module shadowing - CVE-2026-6357
Updated packages:
  • alt-python310-pip_21.3.1-3_all.deb
    sha:090d44dcd3cb838db9ece8c0a15f8b1b36d80122
  • alt-python310-pip-wheel_21.3.1-3_all.deb
    sha:67e860f557cb06085e557134361b204b8920c84d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.