Release date:
2026-09-15 15:04:01 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output()
- debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch:
percent-encode the cookie value with urllib.parse.quote() and wrap it in
decodeURIComponent() instead of escaping only the double quote, so a value
containing cannot break out of the script context (CWE-1336).
- CVE-2026-6019
Updated packages:
-
alt-python312_3.12.14-6_amd64.deb
sha:a2245b227dcd88271a6ea4d41812ce9ac9195660
-
alt-python312-debug_3.12.14-6_amd64.deb
sha:2a111e6424d59bce85cfde7c6ba787ed3f43be96
-
alt-python312-devel_3.12.14-6_amd64.deb
sha:652a1b240b48ead7c443c28c76ddfe40dc8b1a31
-
alt-python312-idle_3.12.14-6_amd64.deb
sha:dc8d172490f4a05749210551d2ac9ddd884c52da
-
alt-python312-libs_3.12.14-6_amd64.deb
sha:037b90d97538bae80c7b4d903cef0f4535f481ae
-
alt-python312-test_3.12.14-6_amd64.deb
sha:b940bb7275bbc0c09d26039b50f7ec458375b945
-
alt-python312-tkinter_3.12.14-6_amd64.deb
sha:9353dd9f3586cdfca38319974762ddef50a32f62
-
alt-python312_3.12.14-6_arm64.deb
sha:09a464872660fcb713023b633534e7810ead2302
-
alt-python312-debug_3.12.14-6_arm64.deb
sha:9a1a0b0e3175060b51171e2a957cae589c9c0ea1
-
alt-python312-devel_3.12.14-6_arm64.deb
sha:6b56018833ef3550c99e6bac45c3667f70ec88fb
-
alt-python312-idle_3.12.14-6_arm64.deb
sha:e172be7aa4cac33574939f2a00ac9b0ec2258431
-
alt-python312-libs_3.12.14-6_arm64.deb
sha:3cda85f37a4b1887421d2590309d6a0b6e96d73a
-
alt-python312-test_3.12.14-6_arm64.deb
sha:d665aaf1e96a74f48ebddd337c4973cb54ca6e50
-
alt-python312-tkinter_3.12.14-6_arm64.deb
sha:4bdd3ec3d67e5c2161820107d4a51bacd7039adc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.