[CLSA-2026:1790780433] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 15:00:47 UTC
Description:
* SECURITY UPDATE: urllib HTTPPasswordMgr credentials were not scoped by URL scheme - debian/patches/CVE-2026-15806.patch: add _reduce_uri_with_scheme() and _is_suburi_with_scheme() to Lib/urllib/request.py and use them in HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth, so credentials registered for an https:// URI are no longer handed out for http:// (cleartext leak after a downgrade or redirect). A URI registered without a scheme still matches any scheme, keeping proxy auth working. - CVE-2026-15806 * SECURITY UPDATE: stringprep applied post-Unicode-3.2.0 case mappings - debian/patches/CVE-2026-17084.patch: regenerate Lib/stringprep.py so b3_exceptions pins to itself every codepoint that the bundled UCD 15.0.0 case-folds but Unicode 3.2.0 does not, so the idna codec no longer folds them against RFC 3454. The table was regenerated with this version's own interpreter; mkstringprep.py and tests updated. - CVE-2026-17084
Updated packages:
  • alt-python312_3.12.14-9_amd64.deb
    sha:10f714b9292714f1f24c198ebc302f107e1a303c
  • alt-python312-debug_3.12.14-9_amd64.deb
    sha:1629744b32f7e7403f838d2a417f82842a4bbfcf
  • alt-python312-devel_3.12.14-9_amd64.deb
    sha:c8b7b4782b50943c71483de3829098191c9c70ae
  • alt-python312-idle_3.12.14-9_amd64.deb
    sha:448f69f4a31b489a9763c0a56b5b9ee048acf32d
  • alt-python312-libs_3.12.14-9_amd64.deb
    sha:9ec10e63ef39cf41876fb10f9e81d2ef46b4cc05
  • alt-python312-test_3.12.14-9_amd64.deb
    sha:7bbcfdedc453bd228a85d6d2fb3e7647a0f3d6dc
  • alt-python312-tkinter_3.12.14-9_amd64.deb
    sha:067d9bf5f606a29834ae91406a1636e6073e815c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.