Release date:
2026-09-30 16:21:49 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr did not scope
credentials by URL scheme (CWE-523, unprotected transport of
credentials). reduce_uri() reduces a URI to an (authority, path) pair and
drops the scheme, so credentials registered for 'https://host/' were also
returned for 'http://host/'. An attacker able to force an HTTPS to HTTP
downgrade or redirect therefore received the Basic-auth credentials in
cleartext.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which
adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses
them in HTTPPasswordMgr.add_password()/find_user_password() and
HTTPPasswordMgrWithPriorAuth.update_authenticated()/is_authenticated().
A URI registered without a scheme still matches any scheme, which keeps
proxy authentication working. Includes upstream's regression tests in
Lib/test/test_urllib2.py.
- CVE-2026-15806
* SECURITY UPDATE: stringprep (and so the 'idna' codec) applied case
mappings from outside Unicode 3.2.0, which RFC 3454 mandates.
map_table_b3() falls back to str.lower() for every codepoint not listed in
b3_exceptions, and str.lower() uses the interpreter's own Unicode 15.1.0
data, so characters that gained a lowercase mapping after 3.2.0
(Cherokee, Georgian Mtavruli, Adlam, Cyrillic Palochka and others) were
case-folded. Different Python versions derived different A-labels for the
same U-label, breaking domain-name comparison and enabling spoofing.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292), which pins every
such codepoint to itself in b3_exceptions, renames the 3.2.0 database
alias to unicodedata_320 and asserts the generating unidata_version,
plus the matching Tools/unicode/mkstringprep.py and
Lib/test/test_codecs.py changes. The upstream table is specific to its
Unicode database, so Lib/stringprep.py was regenerated with this
version's own 3.13.15 interpreter (UCD 15.1.0) rather than copied.
- CVE-2026-17084
Updated packages:
-
alt-python313_3.13.15-6_amd64.deb
sha:cf77da7b9c752482e7ef25053cbc6ba695d8af59
-
alt-python313-debug_3.13.15-6_amd64.deb
sha:489eee10c0a150ddcad8d9df8693c134fed8906c
-
alt-python313-devel_3.13.15-6_amd64.deb
sha:e879c7d9eac788d0bc26daaab0ee709b91db8584
-
alt-python313-idle_3.13.15-6_amd64.deb
sha:9ee8c7345b9fc8694ffd0d7aba91c4c5ef6327da
-
alt-python313-libs_3.13.15-6_amd64.deb
sha:08e4aaa4efb09f978312b3868398e65e589611f1
-
alt-python313-test_3.13.15-6_amd64.deb
sha:cfd8ceec48d69f53f01f3f3c3aad60b60f22856a
-
alt-python313-tkinter_3.13.15-6_amd64.deb
sha:141dd93ee81161479307dcf32f56edad645a9928
-
alt-python313_3.13.15-6_arm64.deb
sha:60081da1f69bac56613862cd0afef0faec34d50b
-
alt-python313-debug_3.13.15-6_arm64.deb
sha:d93cd72296839cd3c6b44add340df08c5d897a44
-
alt-python313-devel_3.13.15-6_arm64.deb
sha:7e4775548b4734d749c0e4cbf1de47c517d92eba
-
alt-python313-idle_3.13.15-6_arm64.deb
sha:08b926db17d3f464d670473c08ae47bbbd9fe72a
-
alt-python313-libs_3.13.15-6_arm64.deb
sha:9f5ef61816a78bb3665e0f845a88af112528222e
-
alt-python313-test_3.13.15-6_arm64.deb
sha:098a6eff212bdb17adbc90d05f0ad6f1d59f0e4f
-
alt-python313-tkinter_3.13.15-6_arm64.deb
sha:41bcd81880e3d0b90b9cc70cbcf425908ec40876
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.