[CLSA-2026:1790769409] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 11:57:01 UTC
Description:
* SECURITY UPDATE: urllib HTTPPasswordMgr credentials were not scoped by URL scheme. reduce_uri() drops the scheme, so credentials registered for "https://host/" were also returned for "http://host/", and an attacker able to force an HTTPS-to-HTTP downgrade or redirect received the Basic-auth credentials in cleartext. A URI registered without a scheme still matches any scheme, which keeps proxy authentication working. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696). The first hunk was re-cut to keep 3.6's list-comprehension spelling in add_password(); the rest is upstream's. - CVE-2026-15806 * SECURITY UPDATE: stringprep applied post-Unicode-3.2.0 case mappings. map_table_b3() falls back to str.lower(), which uses the interpreter's bundled Unicode 9.0.0 data, so characters that gained a lowercase mapping after Unicode 3.2.0 (Cherokee, Palochka, Adlam, ...) were case-folded by the idna codec against RFC 3454. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293). The b3_exceptions table is generated from the running interpreter's UCD, so upstream's Unicode 16.0.0 table does not apply; it was regenerated with this version's own interpreter (UCD 9.0.0, 555 identity entries). - CVE-2026-17084
Updated packages:
  • alt-python36_3.6.15-49_amd64.deb
    sha:13ed4766beb2c8b206c7114197aa6cc9136683f3
  • alt-python36-debug_3.6.15-49_amd64.deb
    sha:3a2b2c87b904e6bb3125bea4f8c0662e9e306648
  • alt-python36-devel_3.6.15-49_amd64.deb
    sha:636d930d4e224a6a29a4af8bceb40b0d0c41cd37
  • alt-python36-libs_3.6.15-49_amd64.deb
    sha:1f6a60e19e1c609df9984e71c499f9c8c64e9558
  • alt-python36-test_3.6.15-49_amd64.deb
    sha:a2068fd29a2896fcdf4324464f7463aa40b9914e
  • alt-python36-tkinter_3.6.15-49_amd64.deb
    sha:04ab8d9280fa1e68be333138e291fa186cf09503
  • alt-python36-tools_3.6.15-49_amd64.deb
    sha:6680f3accb719abd234e840a682f194e76f0040f
  • alt-python36_3.6.15-49_arm64.deb
    sha:7ac4bc0453744403ffa7d7631d1be6914f1abb27
  • alt-python36-debug_3.6.15-49_arm64.deb
    sha:2109092a1709a5f11ed5174a232058b326a6b946
  • alt-python36-devel_3.6.15-49_arm64.deb
    sha:9b588f705cf4b3b20c29ef1486496eaba46a1666
  • alt-python36-libs_3.6.15-49_arm64.deb
    sha:75eadf976010aa1b5f388147e776dfd127852231
  • alt-python36-test_3.6.15-49_arm64.deb
    sha:abf35afc8c580dac11cde1e832c3dbed2f892a99
  • alt-python36-tkinter_3.6.15-49_arm64.deb
    sha:9e280c3dd9f0ff7c6c5238eb36b52cf534ea366f
  • alt-python36-tools_3.6.15-49_arm64.deb
    sha:fec0dbe5c89c5046eefef9f6bafa563e7e7b7f85
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.