Release date:
2026-07-29 14:23:13 UTC
Description:
- CVE-2023-5752: Mercurial revision option injection via VCS URL
- CVE-2025-8869: tar extraction misses symlink target check (no PEP 706 fallback)
- CVE-2026-1703: path traversal via os.path.commonprefix containment check
- CVE-2026-3219: tar/ZIP polyglot archive interpretation conflict
- CVE-2026-6357: post-install self-version check could import malicious wheel content
- Restore el7 byte-compile path (regression from 21.3.1-3): double the
backslashes in the __os_install_post sed capture group so the rewrite
to the alt-python interpreter survives rpm macro expansion on el7
Updated packages:
-
alt-python39-pip-21.3.1-4.el10.noarch.rpm
sha:1e02b0edafaaca6a5f88a05095e83465629e590e4431154683391c4bba138fa8
-
alt-python39-pip-wheel-21.3.1-4.el10.noarch.rpm
sha:41cbc025ea452a54b35ff0912662fc8b7924a598cedb0650acfa6fbfefc5c550
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.