Release date:
2026-07-27 18:30:21 UTC
Description:
- CVE-2023-5752: Mercurial revision option injection in pip VCS URLs
- CVE-2025-8869: symlink target not validated in tar extraction fallback
- CVE-2026-1703: path traversal via os.path.commonprefix in is_within_directory
- CVE-2026-3219: tar/ZIP polyglot archive type confusion in unpack_file
- CVE-2026-6357: pip self-version check runs after install allowing module shadowing
Updated packages:
-
alt-python310-pip-21.3.1-6.el10.noarch.rpm
sha:6e683dd129c4839589080dc91413c351a32d93387504b57530936360bdb5135d
-
alt-python310-pip-wheel-21.3.1-6.el10.noarch.rpm
sha:1f652fa3ec726cc4db0257877a00c6b45586da664a5b49953db2c28adaae2799
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.