Release date:
2026-09-30 10:58:54 UTC
Description:
* SECURITY UPDATE: urllib HTTPPasswordMgr credentials were not scoped by
URL scheme. reduce_uri() drops the scheme, so credentials registered for
"https://host/" were also returned for "http://host/", and an attacker
able to force an HTTPS-to-HTTP downgrade or redirect received the
Basic-auth credentials in cleartext. A URI registered without a scheme
still matches any scheme, which keeps proxy authentication working.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696). The
first hunk was re-cut to keep 3.6's list-comprehension spelling in
add_password(); the rest is upstream's.
- CVE-2026-15806
* SECURITY UPDATE: stringprep applied post-Unicode-3.2.0 case mappings.
map_table_b3() falls back to str.lower(), which uses the interpreter's
bundled Unicode 9.0.0 data, so characters that gained a lowercase
mapping after Unicode 3.2.0 (Cherokee, Palochka, Adlam, ...) were
case-folded by the idna codec against RFC 3454.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293). The
b3_exceptions table is generated from the running interpreter's UCD,
so upstream's Unicode 16.0.0 table does not apply; it was regenerated
with this version's own interpreter (UCD 9.0.0, 555 identity entries).
- CVE-2026-17084
Updated packages:
-
alt-python36_3.6.15-49_amd64.deb
sha:390ea117c4e6399c3eda11c85783579da9dc23e8
-
alt-python36-debug_3.6.15-49_amd64.deb
sha:7f1a6071e3b2e45a7c3e97f5c29a48e0de533ff6
-
alt-python36-devel_3.6.15-49_amd64.deb
sha:01f3ac9316ff6d2c128bdfb350071ac41384e173
-
alt-python36-libs_3.6.15-49_amd64.deb
sha:079d08f3f01e82638a54ae3371eb5b17927044d4
-
alt-python36-test_3.6.15-49_amd64.deb
sha:64ed5f0aa17c762916c4f30cbe3ba19d0e73ebed
-
alt-python36-tkinter_3.6.15-49_amd64.deb
sha:a0b88c79b7fcf78940ab63e95029e44840b02214
-
alt-python36-tools_3.6.15-49_amd64.deb
sha:9713d569b6d7676d8264f6cc34061cc373f452a6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.