[CLSA-2026:1790761234] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 09:40:46 UTC
Description:
* SECURITY UPDATE: urllib.request handed out credentials registered for an https:// URI to the matching http:// URI. HTTPPasswordMgr.reduce_uri() drops the scheme, and add_password()/find_user_password() compared only the reduced (authority, path) pair, so an attacker able to force an HTTPS-to-HTTP downgrade or redirect received the Basic-auth credentials in cleartext. HTTPPasswordMgrWithPriorAuth had the same flaw in update_authenticated()/is_authenticated(). Credentials are now scoped by scheme; a URI registered without a scheme still matches any scheme, which keeps proxy authentication working. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), the 3.13-branch form of the fix. The code change and the three new tests in Lib/test/test_urllib2.py are upstream's verbatim; only hunk offsets were re-cut. - CVE-2026-15806 * SECURITY UPDATE: the stringprep module, used by the "idna" codec (IDNA 2003), applied post-Unicode-3.2.0 case mappings that RFC 3454 forbids. map_table_b3() falls back to str.lower(), which uses the interpreter's own Unicode 11.0.0 data, for every codepoint missing from the generated b3_exceptions table, so characters that gained a lowercase mapping after 3.2.0 (Cherokee, Cyrillic Palochka, Georgian Mtavruli, Adlam, ...) were case-folded, and different Python versions derived different A-labels for the same domain name. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293), the 3.14-branch form of the fix, covering Lib/stringprep.py, Tools/unicode/mkstringprep.py and the new idna test in Lib/test/test_codecs.py. - The b3_exceptions table is generated from the running interpreter's Unicode database, so upstream's Unicode 16.0.0 table does not apply. Lib/stringprep.py was regenerated with the patched mkstringprep.py under this version's own interpreter (Unicode 11.0.0), adding 634 identity entries. The new unidata_version assertion makes a future Unicode database bump fail loudly instead of leaving the table stale. - CVE-2026-17084 * The Misc/NEWS.d fragments and documentation changes of both upstream commits are omitted, as is the Tools/unicode/makeunicodedata.py hook, which only matters when the bundled Unicode database is rebuilt.
Updated packages:
  • alt-python37_3.7.17-34_amd64.deb
    sha:221b8caad5f26ab5bfed8e2c7b78ca0e72d8889e
  • alt-python37-debug_3.7.17-34_amd64.deb
    sha:20ae296ae308b7aef803d4a6603868d3d208d20f
  • alt-python37-devel_3.7.17-34_amd64.deb
    sha:ec49d81cd4bda1bac5e749a204e06861bec1b846
  • alt-python37-libs_3.7.17-34_amd64.deb
    sha:6529fa11e286e4d3e48e64b5bb9b23f66d3aac98
  • alt-python37-test_3.7.17-34_amd64.deb
    sha:54bf54fa199a4391ef52c7a291d3ccc1452ef4d0
  • alt-python37-tkinter_3.7.17-34_amd64.deb
    sha:b6bb9e8c341b25b9044879738083ef63f57525a2
  • alt-python37-tools_3.7.17-34_amd64.deb
    sha:51619316d4f2da94bd3fece395021e9fd694d625
  • alt-python37_3.7.17-34_arm64.deb
    sha:cbe89bbf851055a0d493c43721e6eee82accfb46
  • alt-python37-debug_3.7.17-34_arm64.deb
    sha:78397e4e100b7a40db80fe47b490e59c15e6cfb2
  • alt-python37-devel_3.7.17-34_arm64.deb
    sha:97bd2ba1a275b22bb853dd5453522a3e61b99a30
  • alt-python37-libs_3.7.17-34_arm64.deb
    sha:5eb7087235afb1032b2944046b29d3b27ddb59cd
  • alt-python37-test_3.7.17-34_arm64.deb
    sha:d0ec0c34f88be06a1ae8242d6d787b511b0c13db
  • alt-python37-tkinter_3.7.17-34_arm64.deb
    sha:f4f4f8f454eb6a3398a2806e8665f8b56a44e731
  • alt-python37-tools_3.7.17-34_arm64.deb
    sha:043663b455259a015aea98da043db6aa499ee304
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.