Release date:
2026-09-30 10:36:10 UTC
Description:
* SECURITY UPDATE: urllib HTTPPasswordMgr credentials were not scoped by
URL scheme
- debian/patches/CVE-2026-15806.patch: add _reduce_uri_with_scheme() and
_is_suburi_with_scheme() to Lib/urllib/request.py and use them in
HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth, so credentials
registered for an https:// URI are no longer handed out for http://
(cleartext leak after a downgrade or redirect). A URI registered
without a scheme still matches any scheme, keeping proxy auth working.
- CVE-2026-15806
* SECURITY UPDATE: stringprep applied post-Unicode-3.2.0 case mappings
- debian/patches/CVE-2026-17084.patch: regenerate Lib/stringprep.py so
b3_exceptions pins to itself every codepoint that the bundled UCD
15.0.0 case-folds but Unicode 3.2.0 does not, so the idna codec no
longer folds them against RFC 3454. The table was regenerated with this
version's own interpreter; mkstringprep.py and tests updated.
- CVE-2026-17084
Updated packages:
-
alt-python312_3.12.14-9_amd64.deb
sha:6f4a0ffe3464fb0ad66d6cde0fcc077e7734028d
-
alt-python312-debug_3.12.14-9_amd64.deb
sha:1629744b32f7e7403f838d2a417f82842a4bbfcf
-
alt-python312-devel_3.12.14-9_amd64.deb
sha:9646c52c7f54420f72787d1cdff35519a249a4b8
-
alt-python312-idle_3.12.14-9_amd64.deb
sha:0e077adeffa4ff068b70ca56b5b7467037a13fb3
-
alt-python312-libs_3.12.14-9_amd64.deb
sha:e8389e568967af7999bdfa64c389ed9109fca791
-
alt-python312-test_3.12.14-9_amd64.deb
sha:7c67b2e7d54ec31d192ca0fa9a249e096e5c4c45
-
alt-python312-tkinter_3.12.14-9_amd64.deb
sha:34361369202f23c26a4e214d2f7dbd89b9c43dec
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.