Release date:
2026-09-30 13:20:00 UTC
Description:
* SECURITY UPDATE: urllib.request handed out credentials registered for an
https:// URI to the matching http:// URI. HTTPPasswordMgr.reduce_uri()
drops the scheme, and add_password()/find_user_password() compared only
the reduced (authority, path) pair, so an attacker able to force an
HTTPS-to-HTTP downgrade or redirect received the Basic-auth credentials
in cleartext. HTTPPasswordMgrWithPriorAuth had the same flaw in
update_authenticated()/is_authenticated(). Credentials are now scoped by
scheme; a URI registered without a scheme still matches any scheme, which
keeps proxy authentication working.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), the
3.13-branch form of the fix. The code change and the three new tests in
Lib/test/test_urllib2.py are upstream's verbatim; only hunk offsets
were re-cut.
- CVE-2026-15806
* SECURITY UPDATE: the stringprep module, used by the "idna" codec
(IDNA 2003), applied post-Unicode-3.2.0 case mappings that RFC 3454
forbids. map_table_b3() falls back to str.lower(), which uses the
interpreter's own Unicode 11.0.0 data, for every codepoint missing from
the generated b3_exceptions table, so characters that gained a lowercase
mapping after 3.2.0 (Cherokee, Cyrillic Palochka, Georgian Mtavruli,
Adlam, ...) were case-folded, and different Python versions derived
different A-labels for the same domain name.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293), the
3.14-branch form of the fix, covering Lib/stringprep.py,
Tools/unicode/mkstringprep.py and the new idna test in
Lib/test/test_codecs.py.
- The b3_exceptions table is generated from the running interpreter's
Unicode database, so upstream's Unicode 16.0.0 table does not apply.
Lib/stringprep.py was regenerated with the patched mkstringprep.py
under this version's own interpreter (Unicode 11.0.0), adding 634
identity entries. The new unidata_version assertion makes a future
Unicode database bump fail loudly instead of leaving the table stale.
- CVE-2026-17084
* The Misc/NEWS.d fragments and documentation changes of both upstream
commits are omitted, as is the Tools/unicode/makeunicodedata.py hook,
which only matters when the bundled Unicode database is rebuilt.
Updated packages:
-
alt-python37_3.7.17-34_amd64.deb
sha:ad6421b2745427c777f8d7e48f5816d358a37507
-
alt-python37-debug_3.7.17-34_amd64.deb
sha:4e8005864339ea5ff3aa7289d5f806243fc6e9ae
-
alt-python37-devel_3.7.17-34_amd64.deb
sha:3d48bfb2af5e152bd288966f22ab9fc2e1e6e195
-
alt-python37-libs_3.7.17-34_amd64.deb
sha:309fe467a18587ad7c70141036b7f2489a665a55
-
alt-python37-test_3.7.17-34_amd64.deb
sha:4297919d013798e4d59693e96d8ee27316106014
-
alt-python37-tkinter_3.7.17-34_amd64.deb
sha:aa4fdaa397cb7285a2239b06a859c1481db69cc7
-
alt-python37-tools_3.7.17-34_amd64.deb
sha:51619316d4f2da94bd3fece395021e9fd694d625
-
alt-python37_3.7.17-34_arm64.deb
sha:005ed06d58caacd14e17b9ddd2cdac712133eeb1
-
alt-python37-debug_3.7.17-34_arm64.deb
sha:41bb2d5287d8bde2575aefd65fe640179bed551d
-
alt-python37-devel_3.7.17-34_arm64.deb
sha:b1951f163f27ee931e1f747572d14f13725ad64e
-
alt-python37-libs_3.7.17-34_arm64.deb
sha:409251c117ead260f932b89d81eb1eb67e62f9df
-
alt-python37-test_3.7.17-34_arm64.deb
sha:723526bb84f53ca8d499f4e69d5e1244b5f4891e
-
alt-python37-tkinter_3.7.17-34_arm64.deb
sha:69658370bfee663e1ae71dc17d06e5880eb8e903
-
alt-python37-tools_3.7.17-34_arm64.deb
sha:043663b455259a015aea98da043db6aa499ee304
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.