Release date:
2026-07-30 19:36:45 UTC
Description:
- CVE-2026-3446: stop ignoring excess base64 data after the first padded quad in binascii.a2b_base64(), which backs base64.b64decode()
- CVE-2026-11940: revalidate the hardlink's own shallower path in the tarfile extraction fallback so a symlink cannot escape the destination directory, and pass the extraction filter from extract() down to _extract_one() so the revalidation runs for single-member extraction as well and not only for extractall()
- CVE-2026-6019: percent-encode the cookie value embedded in the http.cookies Morsel.js_output() script snippet and decode it with decodeURIComponent() to prevent breaking out of the script element while keeping UTF-8 values intact
Updated packages:
-
alt-python310-3.10.20-9.el7.x86_64.rpm
sha:97f10bfdf75cef281bee91f920290c1b40d3333c8377b5e7ee5b7959d4cef912
-
alt-python310-debug-3.10.20-9.el7.x86_64.rpm
sha:ed75688cceb4493ce5fa267e8e54d39b635833e169566d9c2d42dd55dbf319d3
-
alt-python310-devel-3.10.20-9.el7.x86_64.rpm
sha:bc7e9f04392d104920c7c1d2fb694cb577255370667e0fbe96e26c844cd92a78
-
alt-python310-idle-3.10.20-9.el7.x86_64.rpm
sha:d305d4348772ec38d230735e0b9bf07ac34b15c0c8094ffb836cd5e0eac7f66d
-
alt-python310-libs-3.10.20-9.el7.x86_64.rpm
sha:53a00b287c04d9d9aad9bbc669621d73a004965fcefc4232cf456205e0e46177
-
alt-python310-test-3.10.20-9.el7.x86_64.rpm
sha:550e6e271a0d5d1cc6d26019f9c51014e3c71b7ac3a7b84aac84873270917be8
-
alt-python310-tkinter-3.10.20-9.el7.x86_64.rpm
sha:c0f553fcf5e2e2dc17c17c62ce66246a539d4e46887f90657baae8dc13348ef8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.