[CLSA-2026:1790786355] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 16:39:28 UTC
Description:
* SECURITY UPDATE: urllib: scope HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth credentials by URL scheme, so credentials registered for an https URI are no longer sent to the http URI of the same host after a downgrade or redirect - CVE-2026-15806 * SECURITY UPDATE: stringprep: pin every codepoint whose case mapping changed after Unicode 3.2.0 in b3_exceptions (regenerated for this interpreter's Unicode 16.0.0 database), so the idna codec no longer applies post-3.2.0 case folding that RFC 3454 forbids - CVE-2026-17084
Updated packages:
  • alt-python314_3.14.7-4_amd64.deb
    sha:e7ea409c0e88e68435a3a41e3877a249c4e84e40
  • alt-python314-debug_3.14.7-4_amd64.deb
    sha:c5d6388cb6b5885d9c72226eaa073a8f8ae139e5
  • alt-python314-devel_3.14.7-4_amd64.deb
    sha:64d41dde318f9cc8550d1d491f31fe6e0552d5a2
  • alt-python314-idle_3.14.7-4_amd64.deb
    sha:dba6429320974de15e1dfe51edfa6a544cb029f0
  • alt-python314-libs_3.14.7-4_amd64.deb
    sha:6789742e7e15916709917253c662f2641adad6df
  • alt-python314-test_3.14.7-4_amd64.deb
    sha:a1232cf017cc50e952eb184c0661e5eb078feee0
  • alt-python314-tkinter_3.14.7-4_amd64.deb
    sha:bb0637e1a2505284672e5922299d1748b7eb8d03
  • alt-python314_3.14.7-4_arm64.deb
    sha:7a293f3cd015bc8ccc9c6c963e8e8fee974c4538
  • alt-python314-debug_3.14.7-4_arm64.deb
    sha:1aebd2b1e895b65f1cb24e63a7a8817a5cc30692
  • alt-python314-devel_3.14.7-4_arm64.deb
    sha:8740749c76a834f4cd1e4fe1b4e8948958558584
  • alt-python314-idle_3.14.7-4_arm64.deb
    sha:7b05505fcf11264a0fbec9b618bd19795e4cda03
  • alt-python314-libs_3.14.7-4_arm64.deb
    sha:05a93f36f501df810e3808442b03ab8a477e6fc6
  • alt-python314-test_3.14.7-4_arm64.deb
    sha:919e58194beeb9fff62cdd8fa424289d17d9aa46
  • alt-python314-tkinter_3.14.7-4_arm64.deb
    sha:a3fbd302492e71ef252679204b7b0eccda243158
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.