Release date:
2026-09-30 11:18:32 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr handed out credentials
across URL schemes (CWE-523, unprotected transport of credentials).
reduce_uri() reduces a URI to (authority, path) and drops the scheme, so
add_password() and find_user_password() - and HTTPPasswordMgrWithPriorAuth
update_authenticated()/is_authenticated() - treated "https://host/" and
"http://host/" as the same URI. Credentials registered only for the
TLS-protected origin were therefore sent in cleartext to an http:// URL
reached through a downgrade or redirect.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which
adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them
in the password managers; a URI registered without a scheme still
matches any scheme, keeping proxy authentication working. Includes the
upstream regression tests in Lib/test/test_urllib2.py.
- CVE-2026-15806
* SECURITY UPDATE: stringprep (the "idna" codec, IDNA 2003) case-folded
characters using post-Unicode-3.2.0 data. RFC 3454 mandates Unicode 3.2.0,
but map_table_b3() falls back to str.lower() for any codepoint missing from
the generated b3_exceptions table, and str.lower() uses the interpreter's
bundled Unicode (12.1.0 here). Characters that gained a lowercase mapping
later - Cherokee, Cyrillic Palochka, Georgian Mtavruli, Adlam, ... - were
folded, so different Python versions derived different A-labels for the
same U-label.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293), which
pins every such codepoint to itself in b3_exceptions, renames the 3.2.0
alias to unicodedata_320 and asserts the bundled unidata_version, plus
the generator change in Tools/unicode/mkstringprep.py and the new idna
test in Lib/test/test_codecs.py. The upstream table is specific to its
UCD, so Lib/stringprep.py was regenerated with this version's own
interpreter (UCD 12.1.0: 641 identity entries added).
- CVE-2026-17084
Updated packages:
-
alt-python38_3.8.20-31_amd64.deb
sha:be23a9310c84ad71a1a8a8c49eb85848ec5c354f
-
alt-python38-debug_3.8.20-31_amd64.deb
sha:424168bf3be9827c96c4a5a418eaf1bd02390bf7
-
alt-python38-devel_3.8.20-31_amd64.deb
sha:2c9287af3d4f03aa30a39d567e39c0d6392b4b5a
-
alt-python38-idle_3.8.20-31_amd64.deb
sha:447f23cc64303ce99d6d0d5c71c5e0e91d98607f
-
alt-python38-libs_3.8.20-31_amd64.deb
sha:da54edad5275cc3f629b8b98dbf64e57f3d74c38
-
alt-python38-test_3.8.20-31_amd64.deb
sha:61d9f6837d9eec86a5a8f6a7f46d04f8f2bd3150
-
alt-python38-tkinter_3.8.20-31_amd64.deb
sha:82f59f1143ef768d2f728f351975c1c3121d0acd
-
alt-python38_3.8.20-31_arm64.deb
sha:e6c7aedb05149cc43a7a12f474cd4ad94f8b79ea
-
alt-python38-debug_3.8.20-31_arm64.deb
sha:97e1d08cead1e9c4aba36553a5f9d29bda149d98
-
alt-python38-devel_3.8.20-31_arm64.deb
sha:adb79e622c007f23e2140a8dfb3b45f06a97e4a9
-
alt-python38-idle_3.8.20-31_arm64.deb
sha:22fcb73190ffa2d9dcebb457a26fb9f44e97f591
-
alt-python38-libs_3.8.20-31_arm64.deb
sha:ee25a804331eb5ffdf55b5ab27fb1258192069ef
-
alt-python38-test_3.8.20-31_arm64.deb
sha:30b8bff5b8ec1a44e51a37ac95f52b70054be9d6
-
alt-python38-tkinter_3.8.20-31_arm64.deb
sha:4f5640b0ca05ff06632838374637bb83d677a216
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.