[CLSA-2026:1790759454] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 09:11:06 UTC
Description:
* SECURITY UPDATE: urllib: scope HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth credentials by URL scheme, so credentials registered for an https URI are no longer sent to the http URI of the same host after a downgrade or redirect - CVE-2026-15806 * SECURITY UPDATE: stringprep: pin every codepoint whose case mapping changed after Unicode 3.2.0 in b3_exceptions (regenerated for this interpreter's Unicode 16.0.0 database), so the idna codec no longer applies post-3.2.0 case folding that RFC 3454 forbids - CVE-2026-17084
Updated packages:
  • alt-python314_3.14.7-4_amd64.deb
    sha:3e8b68399561c8831c5a0081a226c0ecf728482f
  • alt-python314-debug_3.14.7-4_amd64.deb
    sha:233e0a54617029273bae0a35b263fc94dc5d560e
  • alt-python314-devel_3.14.7-4_amd64.deb
    sha:268c65c6deb8b366eddf2facc4c0883a3444d503
  • alt-python314-idle_3.14.7-4_amd64.deb
    sha:6ab63addd985fa7e8bd0d99a35a2016620b25d6e
  • alt-python314-libs_3.14.7-4_amd64.deb
    sha:dd21d61c5443f0028865f2aa51aca2e694061760
  • alt-python314-test_3.14.7-4_amd64.deb
    sha:5360220cda9db2af255667e82648b6b3af1e5a77
  • alt-python314-tkinter_3.14.7-4_amd64.deb
    sha:d34861164b3336e0c42df54ef8fa4bcfdbcc4856
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.