[CLSA-2026:1785171898] alt-python311-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 17:05:15 UTC
Description:
- CVE-2023-5752: Mercurial option injection via crafted VCS revision - CVE-2025-8869: arbitrary file overwrite via symlinks in sdist tarballs - CVE-2026-3219: archive confusion via tar/ZIP polyglot files - CVE-2026-1703: path traversal via string-prefix sibling directories - CVE-2026-6357: code execution via post-install pip self-version check imports
Updated packages:
  • alt-python311-pip-21.3.1-5.el9.noarch.rpm
    sha:ea181741fe0883b0be122d582ddda7caf859a769ba53db9f0d9fb05ed2e256fd
  • alt-python311-pip-wheel-21.3.1-5.el9.noarch.rpm
    sha:baea62a424244211ec23705aadf4d0130045761239b0675d3844e9264e64a3d1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.