[CLSA-2026:1785177652] alt-python38-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 18:41:05 UTC
Description:
- CVE-2023-5752: Mercurial configuration injection via VCS URL revision option - CVE-2025-8869: symlink targets not validated in fallback tar extraction - CVE-2026-1703: path traversal via prefix matching when extracting archives - CVE-2026-3219: concatenated tar/ZIP archives misinterpreted as ZIP - CVE-2026-6357: self-version check could import modules from newly installed wheels
Updated packages:
  • alt-python38-pip-22.2.1-5.el7.noarch.rpm
    sha:c4a66744ec93184b1d61c3a82c9191a633af219925d1f5c8c336ad69afee2a6d
  • alt-python38-pip-wheel-22.2.1-5.el7.noarch.rpm
    sha:608dbbff3f6bafde421e43da3bbc980f5ee7423dc324f2c3d5ad258e3f29335e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.