[CLSA-2026:1785421821] alt-python39: Fix of CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:30:32 UTC
Description:
- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab (gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning when such characters are seen; decoded output is unchanged.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-21.el8.x86_64.rpm
    sha:1da4cf2e8bef9ce1289569780f3ea6f8e31fdfebcbbf9354c8848d0d07aafe31
  • alt-python39-debug-3.9.23-21.el8.x86_64.rpm
    sha:25c38438ee09c25a857e6b06705c0b6639b0ace472c029f4e84e3d2edc1f49ce
  • alt-python39-devel-3.9.23-21.el8.x86_64.rpm
    sha:a25f3397268117b92d3001719436099493096b7224ba0407c29a24f26ff00a3d
  • alt-python39-idle-3.9.23-21.el8.x86_64.rpm
    sha:834d8ad91c2220f5caba55b5fd9b31c083ac743f958c6295394d1102188248fd
  • alt-python39-libs-3.9.23-21.el8.x86_64.rpm
    sha:ff79021ca05600a4115631673234de550dd3dafea2e87ba5475730ab3434da56
  • alt-python39-test-3.9.23-21.el8.x86_64.rpm
    sha:6afc6222b7ebc4fa4aa1835c75fa2b98f27ccab71b3e59e20e954fefd3786f62
  • alt-python39-tkinter-3.9.23-21.el8.x86_64.rpm
    sha:37a2cb394530f132f80cc7b720900e6762aa28e4d91393cedadeeabff43a1846
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.