[CLSA-2026:1785420602] alt-python39: Fix of CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:10:14 UTC
Description:
- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab (gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning when such characters are seen; decoded output is unchanged.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-21.el10.x86_64.rpm
    sha:8c19d13fcd6b644fdbb31ef47011bc93d839b8a57a68092bbbe90f087555c289
  • alt-python39-debug-3.9.23-21.el10.x86_64.rpm
    sha:0b3d91407e33d1ce50254e84d70ef656ad81b18dce99b756e583b7a8b75807e9
  • alt-python39-devel-3.9.23-21.el10.x86_64.rpm
    sha:403a7bf60557d6c3ae582f6248d8e4e8d653d2956a9d011dfb88454fe07303f0
  • alt-python39-idle-3.9.23-21.el10.x86_64.rpm
    sha:81daa7309ff2d2addf82ba8e305e08cfb5aa96abf13fdb242950883f6e6ceb0e
  • alt-python39-libs-3.9.23-21.el10.x86_64.rpm
    sha:828cfe42b851dbb48d78e67254f7befdfc4bbe31a2e2cad7f335532083e236aa
  • alt-python39-test-3.9.23-21.el10.x86_64.rpm
    sha:95ffaff798ac0c01a729817ecc98496be2b7620df6af5570f365b0dcd13f6765
  • alt-python39-tkinter-3.9.23-21.el10.x86_64.rpm
    sha:ca7c4a613b0a52196ce0cdf9a33d8326aa7591c1165d4a43e50d86647013135a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.