[CLSA-2026:1788972384] Fix of 8 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-10-02 07:47:24 UTC
Description:
* SECURITY UPDATE: directory escape via Link.filename decoding the URL path twice - debian/patches/CVE-2026-13346.patch: decode the URL path once and reduce the file name to a single path component - CVE-2026-13346
Updated packages:
  • alt-python37-pip_20.2.4-5_all.deb
    sha:4bb984e717eea259e96fbe2fc2a2515478cff5e9
  • alt-python37-pip-wheel_20.2.4-5_all.deb
    sha:3a0fc096747c191f3a85b9e6e1101d8190a1ec60
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.