Release date:
2026-07-27 17:34:58 UTC
Description:
* SECURITY UPDATE: Mercurial configuration injection via VCS URL revision
- debian/patches/CVE-2023-5752.patch: pass revision as --rev= so it
cannot be misinterpreted as an option by hg
- CVE-2023-5752
* SECURITY UPDATE: symlink targets not validated in tar extraction
- debian/patches/CVE-2025-8869.patch: require symlink members of sdist
tar archives to point at files inside the archive
- CVE-2025-8869
* SECURITY UPDATE: path traversal via prefix matching when extracting
- debian/patches/CVE-2026-1703.patch: use an explicit path-component
containment check instead of commonprefix in is_within_directory
- CVE-2026-1703
* SECURITY UPDATE: concatenated tar/ZIP archives misinterpreted as ZIP
- debian/patches/CVE-2026-3219.patch: pick archive format by content
type, extension, then unambiguous magic signature
- CVE-2026-3219
* SECURITY UPDATE: self-version check ran after installing wheels
- debian/patches/CVE-2026-6357.patch: compute the self-update check
before the install command body runs
- CVE-2026-6357
Updated packages:
-
alt-python38-pip_22.2.1-5_all.deb
sha:5ddb237ef5a0132f47de6636241268be15cdb426
-
alt-python38-pip-wheel_22.2.1-5_all.deb
sha:96ecbc8dc356db9f76a7c94147a2477f315cf6c7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.