[CLSA-2026:1790775811] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 13:43:44 UTC
Description:
* SECURITY UPDATE: urllib: scope HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth credentials by URL scheme, so credentials registered for an https URI are no longer sent to the http URI of the same host after a downgrade or redirect - CVE-2026-15806 * SECURITY UPDATE: stringprep: pin every codepoint whose case mapping changed after Unicode 3.2.0 in b3_exceptions (regenerated for this interpreter's Unicode 16.0.0 database), so the idna codec no longer applies post-3.2.0 case folding that RFC 3454 forbids - CVE-2026-17084
Updated packages:
  • alt-python314_3.14.7-4_amd64.deb
    sha:4014d94b75b37ec2057c525377afe074e7089fe0
  • alt-python314-debug_3.14.7-4_amd64.deb
    sha:233e0a54617029273bae0a35b263fc94dc5d560e
  • alt-python314-devel_3.14.7-4_amd64.deb
    sha:ca432850e72b25593e4364db9c793860377e4297
  • alt-python314-idle_3.14.7-4_amd64.deb
    sha:c5e0685e08e7767848b78aac5d5b6a3aa552f43f
  • alt-python314-libs_3.14.7-4_amd64.deb
    sha:4cf125b35b3bd2c0fcb97cdfc2f7eb5066d26a64
  • alt-python314-test_3.14.7-4_amd64.deb
    sha:4549659c8616651ec715efc2c31bb42066e9630f
  • alt-python314-tkinter_3.14.7-4_amd64.deb
    sha:79b9cde027abaa53e82664a1c297698fa2856199
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.