Release date:
2026-07-30 14:24:47 UTC
Description:
- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always
accepted the standard-alphabet '+' and '/' characters even when an
alternative alphabet excluding them was specified via altchars, so
malformed input could bypass strict-alphabet validation filters
(CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab
(gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning
when such characters are seen; decoded output is unchanged.
Updated packages:
-
alt-python39-3.9.23-21.el7.x86_64.rpm
sha:335d22daad426df0054eaecd2fefe95c924c2d011c5467dd54d65cc5c993a4be
-
alt-python39-debug-3.9.23-21.el7.x86_64.rpm
sha:8018b1869a75aef3af8ee90c758e5bcbb0b771db9605d05e4eec272d84575bed
-
alt-python39-devel-3.9.23-21.el7.x86_64.rpm
sha:65029fe054945bfe8179bd269e77bdc0a575b541e3d841220e8ff316c505fc06
-
alt-python39-idle-3.9.23-21.el7.x86_64.rpm
sha:f8701ee2a56b80abad3bab34ea56a14b76d089c65bb3d888d0ca69af3da71897
-
alt-python39-libs-3.9.23-21.el7.x86_64.rpm
sha:ba87e5987c8c919ff1df6cd9e56d09c2a9512c2d0bd65cb2c0853aaf26973d65
-
alt-python39-test-3.9.23-21.el7.x86_64.rpm
sha:922642fa6dc92e4afe4798d11d0bc65268eb16a62b84096f8d40d4bd4ba88109
-
alt-python39-tkinter-3.9.23-21.el7.x86_64.rpm
sha:42c9720e92805b829ddf75efe8cad5f96a78bd793a1ef7648047b7ce6d254fe2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.