[CLSA-2026:1790765920] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 10:58:54 UTC
Description:
* SECURITY UPDATE: urllib HTTPPasswordMgr credentials were not scoped by URL scheme. reduce_uri() drops the scheme, so credentials registered for "https://host/" were also returned for "http://host/", and an attacker able to force an HTTPS-to-HTTP downgrade or redirect received the Basic-auth credentials in cleartext. A URI registered without a scheme still matches any scheme, which keeps proxy authentication working. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696). The first hunk was re-cut to keep 3.6's list-comprehension spelling in add_password(); the rest is upstream's. - CVE-2026-15806 * SECURITY UPDATE: stringprep applied post-Unicode-3.2.0 case mappings. map_table_b3() falls back to str.lower(), which uses the interpreter's bundled Unicode 9.0.0 data, so characters that gained a lowercase mapping after Unicode 3.2.0 (Cherokee, Palochka, Adlam, ...) were case-folded by the idna codec against RFC 3454. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293). The b3_exceptions table is generated from the running interpreter's UCD, so upstream's Unicode 16.0.0 table does not apply; it was regenerated with this version's own interpreter (UCD 9.0.0, 555 identity entries). - CVE-2026-17084
Updated packages:
  • alt-python36_3.6.15-49_amd64.deb
    sha:390ea117c4e6399c3eda11c85783579da9dc23e8
  • alt-python36-debug_3.6.15-49_amd64.deb
    sha:7f1a6071e3b2e45a7c3e97f5c29a48e0de533ff6
  • alt-python36-devel_3.6.15-49_amd64.deb
    sha:01f3ac9316ff6d2c128bdfb350071ac41384e173
  • alt-python36-libs_3.6.15-49_amd64.deb
    sha:079d08f3f01e82638a54ae3371eb5b17927044d4
  • alt-python36-test_3.6.15-49_amd64.deb
    sha:64ed5f0aa17c762916c4f30cbe3ba19d0e73ebed
  • alt-python36-tkinter_3.6.15-49_amd64.deb
    sha:a0b88c79b7fcf78940ab63e95029e44840b02214
  • alt-python36-tools_3.6.15-49_amd64.deb
    sha:9713d569b6d7676d8264f6cc34061cc373f452a6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.