[CLSA-2026:1789480575] Fix CVE(s): CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-15 13:56:26 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output() - debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch: percent-encode the cookie value with urllib.parse.quote() and wrap it in decodeURIComponent() instead of escaping only the double quote, so a value containing cannot break out of the script context (CWE-1336). - CVE-2026-6019
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-6_amd64.deb
    sha:5ed306c517280c404a1f17aac147503403c72532
  • alt-python312-debug_3.12.14-6_amd64.deb
    sha:2a111e6424d59bce85cfde7c6ba787ed3f43be96
  • alt-python312-devel_3.12.14-6_amd64.deb
    sha:f6ee2f3b431aecb28307578a5a8c8ae6dc2603b9
  • alt-python312-idle_3.12.14-6_amd64.deb
    sha:5a932d4c5244cc6ec740045b5d3c95bfe85cce20
  • alt-python312-libs_3.12.14-6_amd64.deb
    sha:b790e18e33919ac61c89ab678f2aae1be3575263
  • alt-python312-test_3.12.14-6_amd64.deb
    sha:8fb13f24c3b3fd038cbff670d70fa6feb49a519f
  • alt-python312-tkinter_3.12.14-6_amd64.deb
    sha:b755e05e942422672eb1d32da0a2f00e62cb11ed
  • alt-python312_3.12.14-6_arm64.deb
    sha:549483550152ab9da202604196d388416bf4e73e
  • alt-python312-debug_3.12.14-6_arm64.deb
    sha:9a1a0b0e3175060b51171e2a957cae589c9c0ea1
  • alt-python312-devel_3.12.14-6_arm64.deb
    sha:897d0e68614d2e720cc0ad0fa3c7c188c34aeeaa
  • alt-python312-idle_3.12.14-6_arm64.deb
    sha:30c5023833ea43154849f2169add7f1bdbba8ca5
  • alt-python312-libs_3.12.14-6_arm64.deb
    sha:95d3fa99e791e3a35800170daac6884125356369
  • alt-python312-test_3.12.14-6_arm64.deb
    sha:a167050d8d49a6e5e1e828f72fdc0f28689376bf
  • alt-python312-tkinter_3.12.14-6_arm64.deb
    sha:cdc29a8a3b1208808d32b3cef1ad6c878c31c56c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.