Release date:
2026-07-30 18:52:00 UTC
Description:
- CVE-2026-3446: stop ignoring excess base64 data after the first padded quad in binascii.a2b_base64(), which backs base64.b64decode()
- CVE-2026-11940: revalidate the hardlink's own shallower path in the tarfile extraction fallback so a symlink cannot escape the destination directory, and pass the extraction filter from extract() down to _extract_one() so the revalidation runs for single-member extraction as well and not only for extractall()
- CVE-2026-6019: percent-encode the cookie value embedded in the http.cookies Morsel.js_output() script snippet and decode it with decodeURIComponent() to prevent breaking out of the script element while keeping UTF-8 values intact
Updated packages:
-
alt-python310-3.10.20-9.el8.x86_64.rpm
sha:b818dc432572f85680ba9ad9da5d5e4eeb175a0ab44a54255f6c252432f88cb3
-
alt-python310-debug-3.10.20-9.el8.x86_64.rpm
sha:f64144c60dbb44b1394015ae33c431b84b84c9252c9bf9972fafe128852cdf4f
-
alt-python310-devel-3.10.20-9.el8.x86_64.rpm
sha:3ac6cee8d3ddd0bdc09d747f3da2ab1f6a1e33faa5ee23dff6616c0e44bf2c9f
-
alt-python310-idle-3.10.20-9.el8.x86_64.rpm
sha:aec4dcf2582ad18693808b83329e7a017ded0372972781d8989899e3140b0916
-
alt-python310-libs-3.10.20-9.el8.x86_64.rpm
sha:c9c856c06fb92711fff8dd4a88f80605810ceac7b45e3eb1c73606f65447ecab
-
alt-python310-test-3.10.20-9.el8.x86_64.rpm
sha:1e0617e21b25b1b8d13b403d3c6e1e294c365d90c87686b8db8c19c3b2cc0c41
-
alt-python310-tkinter-3.10.20-9.el8.x86_64.rpm
sha:f48a93cab562214a6816a464091b39f8153ec1b4577f35bfea477e1782ec436e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.