[CLSA-2026:1790768893] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 11:48:25 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr did not scope credentials by URL scheme (CWE-523, unprotected transport of credentials). reduce_uri() reduces a URI to an (authority, path) pair and drops the scheme, so credentials registered for 'https://host/' were also returned for 'http://host/'. An attacker able to force an HTTPS to HTTP downgrade or redirect therefore received the Basic-auth credentials in cleartext. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them in HTTPPasswordMgr.add_password()/find_user_password() and HTTPPasswordMgrWithPriorAuth.update_authenticated()/is_authenticated(). A URI registered without a scheme still matches any scheme, which keeps proxy authentication working. Includes upstream's regression tests in Lib/test/test_urllib2.py. - CVE-2026-15806 * SECURITY UPDATE: stringprep (and so the 'idna' codec) applied case mappings from outside Unicode 3.2.0, which RFC 3454 mandates. map_table_b3() falls back to str.lower() for every codepoint not listed in b3_exceptions, and str.lower() uses the interpreter's own Unicode 15.1.0 data, so characters that gained a lowercase mapping after 3.2.0 (Cherokee, Georgian Mtavruli, Adlam, Cyrillic Palochka and others) were case-folded. Different Python versions derived different A-labels for the same U-label, breaking domain-name comparison and enabling spoofing. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292), which pins every such codepoint to itself in b3_exceptions, renames the 3.2.0 database alias to unicodedata_320 and asserts the generating unidata_version, plus the matching Tools/unicode/mkstringprep.py and Lib/test/test_codecs.py changes. The upstream table is specific to its Unicode database, so Lib/stringprep.py was regenerated with this version's own 3.13.15 interpreter (UCD 15.1.0) rather than copied. - CVE-2026-17084
Updated packages:
  • alt-python313_3.13.15-6_amd64.deb
    sha:4219cdcc325be23d6ad1675144a4a1e1e9fb7f5e
  • alt-python313-debug_3.13.15-6_amd64.deb
    sha:489eee10c0a150ddcad8d9df8693c134fed8906c
  • alt-python313-devel_3.13.15-6_amd64.deb
    sha:261332bac03bcfb3f1ab25688bfa9d16d49c6709
  • alt-python313-idle_3.13.15-6_amd64.deb
    sha:96a9e929d81ea9b0541e324b84cf67375a77f5f0
  • alt-python313-libs_3.13.15-6_amd64.deb
    sha:61d32f2cff5b9ba0acd1694701d45bf3bcaeb7b7
  • alt-python313-test_3.13.15-6_amd64.deb
    sha:9cc6b8e5c02ffe0764d7d197c658a248b1955750
  • alt-python313-tkinter_3.13.15-6_amd64.deb
    sha:d68ed352bf50446090cbd3790add592cf8e88c70
  • alt-python313_3.13.15-6_arm64.deb
    sha:406ab0750ca173a6d5866fcf3985dc3aca806668
  • alt-python313-debug_3.13.15-6_arm64.deb
    sha:d93cd72296839cd3c6b44add340df08c5d897a44
  • alt-python313-devel_3.13.15-6_arm64.deb
    sha:b5968f471cab3f5c15a3394c509281d01319bcf4
  • alt-python313-idle_3.13.15-6_arm64.deb
    sha:da1c700485b18a261dcd8d810dc37ef9ae2b1d7d
  • alt-python313-libs_3.13.15-6_arm64.deb
    sha:6f5b853b4c996025fd0c77cf8403968d015b34b5
  • alt-python313-test_3.13.15-6_arm64.deb
    sha:755f817ef508b583e4fbd2e11477121108f970fa
  • alt-python313-tkinter_3.13.15-6_arm64.deb
    sha:b8ef2d64ab88c95538a63d2dbde6e0f189de8824
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.