Release date:
2026-09-30 15:28:27 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr did not scope
credentials by URL scheme (CWE-523, unprotected transport of
credentials). reduce_uri() reduces a URI to an (authority, path) pair and
drops the scheme, so credentials registered for 'https://host/' were also
returned for 'http://host/'. An attacker able to force an HTTPS to HTTP
downgrade or redirect therefore received the Basic-auth credentials in
cleartext.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which
adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses
them in HTTPPasswordMgr.add_password()/find_user_password() and
HTTPPasswordMgrWithPriorAuth.update_authenticated()/is_authenticated().
A URI registered without a scheme still matches any scheme, which keeps
proxy authentication working. Includes upstream's regression tests in
Lib/test/test_urllib2.py.
- CVE-2026-15806
* SECURITY UPDATE: stringprep (and so the 'idna' codec) applied case
mappings from outside Unicode 3.2.0, which RFC 3454 mandates.
map_table_b3() falls back to str.lower() for every codepoint not listed in
b3_exceptions, and str.lower() uses the interpreter's own Unicode 13.0.0
data, so characters that gained a lowercase mapping after 3.2.0
(Cherokee, Georgian Mtavruli, Adlam, Cyrillic Palochka and others) were
case-folded. Different Python versions derived different A-labels for the
same U-label, breaking domain-name comparison and enabling spoofing.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (cherry-pick of
7e109d084d55e7eb25837a5f3b47ef9beee547bc), which pins every such
codepoint to itself in b3_exceptions, renames the 3.2.0 database alias
to unicodedata_320 and asserts the generating unidata_version, plus the
matching Tools/unicode/mkstringprep.py and Lib/test/test_codecs.py
changes. The upstream table is specific to its Unicode database, so
Lib/stringprep.py was regenerated with this version's own 3.9.23
interpreter (UCD 13.0.0) rather than copied.
- CVE-2026-17084
Updated packages:
-
alt-python39_3.9.23-32_amd64.deb
sha:2bfc769dd4f7d59bf1eb4bae003853cc15661bcb
-
alt-python39-debug_3.9.23-32_amd64.deb
sha:2377fa4b7144c42d7578b2829b8827abe70d369a
-
alt-python39-devel_3.9.23-32_amd64.deb
sha:b4d3cf903dc0d36eb168a95062942855bfd2b57f
-
alt-python39-idle_3.9.23-32_amd64.deb
sha:8c203fdebe673bde96faa5706605472f24d09d7b
-
alt-python39-libs_3.9.23-32_amd64.deb
sha:2b5b39bf0b5cb82a62fca7e11047139a4e99bebe
-
alt-python39-test_3.9.23-32_amd64.deb
sha:573cf931c6b361ce86dbeff344a41b34deb7a2e9
-
alt-python39-tkinter_3.9.23-32_amd64.deb
sha:cc11d6e9133b30f0188604fb33fbf49738b3b752
-
alt-python39_3.9.23-32_arm64.deb
sha:a0366bf94365b604fb241dd08056afad26bac391
-
alt-python39-debug_3.9.23-32_arm64.deb
sha:55bd3316cea665b84c126cfeeb89412d10018813
-
alt-python39-devel_3.9.23-32_arm64.deb
sha:8ec49821f39faa5972ddc63988588e453a1ad84f
-
alt-python39-idle_3.9.23-32_arm64.deb
sha:ef8d572c1d36148f7aa07aad7136c666de4587eb
-
alt-python39-libs_3.9.23-32_arm64.deb
sha:71358367e37db61ff177f5420040a3e1a1040e6f
-
alt-python39-test_3.9.23-32_arm64.deb
sha:556d3f8236c8cf3a37bed1d9bebf8a92903f5aab
-
alt-python39-tkinter_3.9.23-32_arm64.deb
sha:726d63a65983f6e5f424c2f412e99a57c2e04268
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.