[CLSA-2026:1785173409] alt-python38-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 17:30:24 UTC
Description:
- CVE-2023-5752: Mercurial configuration injection via VCS URL revision option - CVE-2025-8869: symlink targets not validated in fallback tar extraction - CVE-2026-1703: path traversal via prefix matching when extracting archives - CVE-2026-3219: concatenated tar/ZIP archives misinterpreted as ZIP - CVE-2026-6357: self-version check could import modules from newly installed wheels
Updated packages:
  • alt-python38-pip-22.2.1-5.el9.noarch.rpm
    sha:f98ba39c2511370de5434fb75c2f423523677dc90cd2886ef94bd59aca478c63
  • alt-python38-pip-wheel-22.2.1-5.el9.noarch.rpm
    sha:a1be87084a6e7f588c976d06037f996cd2fdfb40bd40f5966b807e0db0d3ebf1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.