[CLSA-2026:1790782090] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 15:28:27 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr did not scope credentials by URL scheme (CWE-523, unprotected transport of credentials). reduce_uri() reduces a URI to an (authority, path) pair and drops the scheme, so credentials registered for 'https://host/' were also returned for 'http://host/'. An attacker able to force an HTTPS to HTTP downgrade or redirect therefore received the Basic-auth credentials in cleartext. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them in HTTPPasswordMgr.add_password()/find_user_password() and HTTPPasswordMgrWithPriorAuth.update_authenticated()/is_authenticated(). A URI registered without a scheme still matches any scheme, which keeps proxy authentication working. Includes upstream's regression tests in Lib/test/test_urllib2.py. - CVE-2026-15806 * SECURITY UPDATE: stringprep (and so the 'idna' codec) applied case mappings from outside Unicode 3.2.0, which RFC 3454 mandates. map_table_b3() falls back to str.lower() for every codepoint not listed in b3_exceptions, and str.lower() uses the interpreter's own Unicode 13.0.0 data, so characters that gained a lowercase mapping after 3.2.0 (Cherokee, Georgian Mtavruli, Adlam, Cyrillic Palochka and others) were case-folded. Different Python versions derived different A-labels for the same U-label, breaking domain-name comparison and enabling spoofing. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (cherry-pick of 7e109d084d55e7eb25837a5f3b47ef9beee547bc), which pins every such codepoint to itself in b3_exceptions, renames the 3.2.0 database alias to unicodedata_320 and asserts the generating unidata_version, plus the matching Tools/unicode/mkstringprep.py and Lib/test/test_codecs.py changes. The upstream table is specific to its Unicode database, so Lib/stringprep.py was regenerated with this version's own 3.9.23 interpreter (UCD 13.0.0) rather than copied. - CVE-2026-17084
Updated packages:
  • alt-python39_3.9.23-32_amd64.deb
    sha:2bfc769dd4f7d59bf1eb4bae003853cc15661bcb
  • alt-python39-debug_3.9.23-32_amd64.deb
    sha:2377fa4b7144c42d7578b2829b8827abe70d369a
  • alt-python39-devel_3.9.23-32_amd64.deb
    sha:b4d3cf903dc0d36eb168a95062942855bfd2b57f
  • alt-python39-idle_3.9.23-32_amd64.deb
    sha:8c203fdebe673bde96faa5706605472f24d09d7b
  • alt-python39-libs_3.9.23-32_amd64.deb
    sha:2b5b39bf0b5cb82a62fca7e11047139a4e99bebe
  • alt-python39-test_3.9.23-32_amd64.deb
    sha:573cf931c6b361ce86dbeff344a41b34deb7a2e9
  • alt-python39-tkinter_3.9.23-32_amd64.deb
    sha:cc11d6e9133b30f0188604fb33fbf49738b3b752
  • alt-python39_3.9.23-32_arm64.deb
    sha:a0366bf94365b604fb241dd08056afad26bac391
  • alt-python39-debug_3.9.23-32_arm64.deb
    sha:55bd3316cea665b84c126cfeeb89412d10018813
  • alt-python39-devel_3.9.23-32_arm64.deb
    sha:8ec49821f39faa5972ddc63988588e453a1ad84f
  • alt-python39-idle_3.9.23-32_arm64.deb
    sha:ef8d572c1d36148f7aa07aad7136c666de4587eb
  • alt-python39-libs_3.9.23-32_arm64.deb
    sha:71358367e37db61ff177f5420040a3e1a1040e6f
  • alt-python39-test_3.9.23-32_arm64.deb
    sha:556d3f8236c8cf3a37bed1d9bebf8a92903f5aab
  • alt-python39-tkinter_3.9.23-32_arm64.deb
    sha:726d63a65983f6e5f424c2f412e99a57c2e04268
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.