[CLSA-2026:1790768417] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 11:40:28 UTC
Description:
* SECURITY UPDATE: urllib handed out HTTPS credentials for plain-HTTP URLs - debian/patches/CVE-2026-15806.patch: scope HTTPPasswordMgr credentials by URL scheme. reduce_uri() drops the scheme, so credentials registered for "https://host/" were also returned for "http://host/", and an attacker able to force an HTTPS to HTTP downgrade or redirect received them in cleartext. Adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them in HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth. A URI registered without a scheme still matches any scheme, so proxy authentication is unchanged. Carries upstream's regression tests (gh-155694) - CVE-2026-15806 * SECURITY UPDATE: stringprep case-folded characters that Unicode 3.2.0 leaves alone - debian/patches/CVE-2026-17084.patch: map_table_b3() fell back to str.lower(), which uses the interpreter's own Unicode 13.0.0 data instead of the Unicode 3.2.0 data RFC 3454 mandates, so the idna codec folded e.g. Cherokee, Georgian Mtavruli and Cyrillic Palochka and could derive a different A-label for the same domain name. Regenerates Lib/stringprep.py so b3_exceptions pins every such codepoint to itself, and updates Tools/unicode/mkstringprep.py accordingly. The table was regenerated with this version's own interpreter (UCD 13.0.0), because the upstream table is specific to the Unicode version it was built with. Carries upstream's idna regression test (gh-155292) - CVE-2026-17084
Updated packages:
  • alt-python310_3.10.21-4_amd64.deb
    sha:ea712bc547dba50d6c55a54c93c687c456522692
  • alt-python310-debug_3.10.21-4_amd64.deb
    sha:7dd1426a25c8de17e33c3f3f5057a9a5ea731215
  • alt-python310-devel_3.10.21-4_amd64.deb
    sha:d8e4297edf90bab2a8c30861459478a0349dc3b4
  • alt-python310-idle_3.10.21-4_amd64.deb
    sha:741d3b36fbfb3bf6a40d61db6147bbcfc87480db
  • alt-python310-libs_3.10.21-4_amd64.deb
    sha:7b55af719de50d0c905d528e925d5b8894254bfc
  • alt-python310-test_3.10.21-4_amd64.deb
    sha:8118e46e3cbc9030379197f3fee2d8b952811c9e
  • alt-python310-tkinter_3.10.21-4_amd64.deb
    sha:946c1ba4b93278a654708176ed226ffdfaf60b14
  • alt-python310_3.10.21-4_arm64.deb
    sha:6fb85d4c77976a12ba4d75eddb38be8c66c0433f
  • alt-python310-debug_3.10.21-4_arm64.deb
    sha:d21985ee4aca2c99358aa247e4645701ea6d0935
  • alt-python310-devel_3.10.21-4_arm64.deb
    sha:e968a778c436e576906e48d545af71e471a4565e
  • alt-python310-idle_3.10.21-4_arm64.deb
    sha:79b984f25f298abe42a3ebe874db3135d1d4c2ea
  • alt-python310-libs_3.10.21-4_arm64.deb
    sha:ab5c5c45fcdea4d2220df26a13e97431c7c753bf
  • alt-python310-test_3.10.21-4_arm64.deb
    sha:78e430ef2a571820031965d6f465c42fdafb4bba
  • alt-python310-tkinter_3.10.21-4_arm64.deb
    sha:6201c8ba273d658e2706313ab04e6185a7329ddb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.