Release date:
2026-07-29 16:08:07 UTC
Description:
- CVE-2026-0864: normalize CR/CRLF line endings in configparser writes to prevent key/value injection
- CVE-2026-1502: reject CR/LF in http.client proxy CONNECT tunnel host and headers
- CVE-2026-3276: fix O(n^2) canonical ordering in unicodedata.normalize() (DoS on crafted combining sequences)
- CVE-2026-6019: percent-encode cookie values embedded in http.cookies js_output() to prevent script injection (XSS)
- CVE-2026-7774: validate written link target in tarfile data filter to prevent path traversal
- CVE-2026-8328: apply CVE-2021-4189 PASV peer-address check to ftplib.ftpcp() to prevent data-connection SSRF
- CVE-2026-11940: fix symlink escape via tarfile hardlink-extraction fallback (path traversal)
- CVE-2026-11972: make tarfile._Stream.seek() break at EOF to prevent infinite-loop DoS on crafted stream archives
Updated packages:
-
alt-python311-3.11.15-5.el8.x86_64.rpm
sha:d0195c9f5e8369129225aceb773f55f33be7b08ed534cd100de7253c9825c28f
-
alt-python311-debug-3.11.15-5.el8.x86_64.rpm
sha:a103e51370b44347cd9cfcfc321ba0253d75ef0aebcaeb70d1c1e9a1da88bf00
-
alt-python311-devel-3.11.15-5.el8.x86_64.rpm
sha:fadbc1af905197f4a689310823be15323b042196f9eb322af8732836fa0d2a86
-
alt-python311-idle-3.11.15-5.el8.x86_64.rpm
sha:b3b4a90c63f49022c98e0f81afc903bb8e019ccd50a464d88dbe71054d8d8ad8
-
alt-python311-libs-3.11.15-5.el8.x86_64.rpm
sha:584e0ebedf6b13c2ce3264aa23285e2ca73436817c5100d602fbad13a295b690
-
alt-python311-test-3.11.15-5.el8.x86_64.rpm
sha:d9a1552b9aef8468154a38f1f3cc52137a057d15c3a84ed744264ea7b0490741
-
alt-python311-tkinter-3.11.15-5.el8.x86_64.rpm
sha:3d84ff8f574012ef720a4a8ba301fa75fd0b294439549b071eeb1cee3478ee8c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.