[CLSA-2026:1789552190] alt-python312: Fix of CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-16 09:49:59 UTC
Description:
- CVE-2026-6019: percent-encode cookie values embedded in JavaScript by http.cookies.Morsel.js_output() and wrap them in decodeURIComponent(), so a value containing can no longer break out of the script context
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-5.el7.x86_64.rpm
    sha:3a4e0725bf8edf7b3df8f73f3a20fdd566c6304e91c0e91a84f0e8202c7389a6
  • alt-python312-debug-3.12.14-5.el7.x86_64.rpm
    sha:2f1a36751ec39b5d17d93f5f138ffa7038955b875d88f724889cebe35371de30
  • alt-python312-devel-3.12.14-5.el7.x86_64.rpm
    sha:4a0a088255874f3c6fcc37486befca01c53ae3a8ca52158d175c87a516c4904d
  • alt-python312-idle-3.12.14-5.el7.x86_64.rpm
    sha:321f1e1d45b3674dd9ad630cd6767068acc083cb4945e674ab2f1d64f1572b44
  • alt-python312-libs-3.12.14-5.el7.x86_64.rpm
    sha:ea6b85feceea04a44bd76840bb3c28bb739c400eb115f57cb26d948cb62904b4
  • alt-python312-test-3.12.14-5.el7.x86_64.rpm
    sha:7fca7f498e444befe058319c2437de54b8bcf140d969a6e50811724351fff15d
  • alt-python312-tkinter-3.12.14-5.el7.x86_64.rpm
    sha:1f24e538c3c5dfb786680e5e94193e80452e1b07b993881cebacf6f5a6d709a0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.