[CLSA-2026:1790772377] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 12:46:36 UTC
Description:
* SECURITY UPDATE: urllib HTTPPasswordMgr credentials were not scoped by URL scheme. reduce_uri() drops the scheme, so credentials registered for "https://host/" were also returned for "http://host/", and an attacker able to force an HTTPS-to-HTTP downgrade or redirect received the Basic-auth credentials in cleartext. A URI registered without a scheme still matches any scheme, which keeps proxy authentication working. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696). The first hunk was re-cut to keep 3.6's list-comprehension spelling in add_password(); the rest is upstream's. - CVE-2026-15806 * SECURITY UPDATE: stringprep applied post-Unicode-3.2.0 case mappings. map_table_b3() falls back to str.lower(), which uses the interpreter's bundled Unicode 9.0.0 data, so characters that gained a lowercase mapping after Unicode 3.2.0 (Cherokee, Palochka, Adlam, ...) were case-folded by the idna codec against RFC 3454. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293). The b3_exceptions table is generated from the running interpreter's UCD, so upstream's Unicode 16.0.0 table does not apply; it was regenerated with this version's own interpreter (UCD 9.0.0, 555 identity entries). - CVE-2026-17084
Updated packages:
  • alt-python36_3.6.15-49_amd64.deb
    sha:2568fbc294ddaea270ef9dbffc48a620d725b496
  • alt-python36-debug_3.6.15-49_amd64.deb
    sha:f100332ace2b6468d38cd3cad75f0092aaab5fa5
  • alt-python36-devel_3.6.15-49_amd64.deb
    sha:f92e5eb131eb51ceb24da4988600b43e3eb81b68
  • alt-python36-libs_3.6.15-49_amd64.deb
    sha:61c37e1a63c8cf0124a9b0b04f77cda7503c1826
  • alt-python36-test_3.6.15-49_amd64.deb
    sha:046f204959382273b258322843ce3e68e68c7b4f
  • alt-python36-tkinter_3.6.15-49_amd64.deb
    sha:1a757284a952fbe7ca68c0e5f9dde4b49e891c1e
  • alt-python36-tools_3.6.15-49_amd64.deb
    sha:4d822a6ae82a340fa8deeb1971bb1183fa70a748
  • alt-python36_3.6.15-49_arm64.deb
    sha:f33916529bc69e9c049b10460d00af39ac2363e2
  • alt-python36-debug_3.6.15-49_arm64.deb
    sha:87a26c98616c4a7d8e0537afb7e5c0cd601c9193
  • alt-python36-devel_3.6.15-49_arm64.deb
    sha:9dc3fdb18bbbb3ea9e9708c79c108121d60a4d47
  • alt-python36-libs_3.6.15-49_arm64.deb
    sha:712bb390042b58ae573669afb831cd4e918b15a8
  • alt-python36-test_3.6.15-49_arm64.deb
    sha:69475dc186cc55f9dfd6b4a155bd9e959b9ba3af
  • alt-python36-tkinter_3.6.15-49_arm64.deb
    sha:08945c932bd95c4c7dec2ba6f74bccb89d7957c6
  • alt-python36-tools_3.6.15-49_arm64.deb
    sha:90a7032a15541bb84503f48c5782310941f3e8ec
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.