Release date:
2026-07-30 14:35:35 UTC
Description:
- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always
accepted the standard-alphabet '+' and '/' characters even when an
alternative alphabet excluding them was specified via altchars, so
malformed input could bypass strict-alphabet validation filters
(CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab
(gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning
when such characters are seen; decoded output is unchanged.
Updated packages:
-
alt-python39-3.9.23-21.el9.x86_64.rpm
sha:2434702663f7b84fcf8d2f3aeaa2436f772945091ec08cd9aa9ac68a13fa2668
-
alt-python39-debug-3.9.23-21.el9.x86_64.rpm
sha:08779020ead59ac475b4da1278a701b6c86dd4077961bf09b3bbde5ad39cb5a9
-
alt-python39-devel-3.9.23-21.el9.x86_64.rpm
sha:9d4ad9201d2ff4bf8b9031f9bfe77504a9db5d9a8c8ee2cdd901b70b41e500df
-
alt-python39-idle-3.9.23-21.el9.x86_64.rpm
sha:cf26200c4551dab12825bc37f932863da56c443ccb1d7fe4b2df93f8697e8cad
-
alt-python39-libs-3.9.23-21.el9.x86_64.rpm
sha:f2fa50bd142892bed92b4039d76567a378de2ed7857561606f72cf3b6c89caf3
-
alt-python39-test-3.9.23-21.el9.x86_64.rpm
sha:02458f330fbf8e5e813f3d56650f48b14233a6cfe5714f9f91d8b456704fe379
-
alt-python39-tkinter-3.9.23-21.el9.x86_64.rpm
sha:864990e5cf4e99e50758198100546c6b278265b9af98d70b249691963e8eb3e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.