Release date:
2026-09-30 14:47:43 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr handed out credentials
across URL schemes (CWE-523, unprotected transport of credentials).
reduce_uri() reduces a URI to (authority, path) and drops the scheme, so
add_password() and find_user_password() - and HTTPPasswordMgrWithPriorAuth
update_authenticated()/is_authenticated() - treated "https://host/" and
"http://host/" as the same URI. Credentials registered only for the
TLS-protected origin were therefore sent in cleartext to an http:// URL
reached through a downgrade or redirect.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which
adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them
in the password managers; a URI registered without a scheme still
matches any scheme, keeping proxy authentication working. Includes the
upstream regression tests in Lib/test/test_urllib2.py.
- CVE-2026-15806
* SECURITY UPDATE: stringprep (the "idna" codec, IDNA 2003) case-folded
characters using post-Unicode-3.2.0 data. RFC 3454 mandates Unicode 3.2.0,
but map_table_b3() falls back to str.lower() for any codepoint missing from
the generated b3_exceptions table, and str.lower() uses the interpreter's
bundled Unicode (12.1.0 here). Characters that gained a lowercase mapping
later - Cherokee, Cyrillic Palochka, Georgian Mtavruli, Adlam, ... - were
folded, so different Python versions derived different A-labels for the
same U-label.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293), which
pins every such codepoint to itself in b3_exceptions, renames the 3.2.0
alias to unicodedata_320 and asserts the bundled unidata_version, plus
the generator change in Tools/unicode/mkstringprep.py and the new idna
test in Lib/test/test_codecs.py. The upstream table is specific to its
UCD, so Lib/stringprep.py was regenerated with this version's own
interpreter (UCD 12.1.0: 641 identity entries added).
- CVE-2026-17084
Updated packages:
-
alt-python38_3.8.20-31_amd64.deb
sha:7e9a7000f4e11c440fed25fac5d9f9023b8422e2
-
alt-python38-debug_3.8.20-31_amd64.deb
sha:9c65b4551a540ca06e1d56fddf88dda629a68fb8
-
alt-python38-devel_3.8.20-31_amd64.deb
sha:ff3fed71836a0e731937d5d180b52f7da994518a
-
alt-python38-idle_3.8.20-31_amd64.deb
sha:8ddc3d7e89e0c7c7878ee671d7488efefec6211a
-
alt-python38-libs_3.8.20-31_amd64.deb
sha:684aa7da24ef507e26ea08053ee19567ee411938
-
alt-python38-test_3.8.20-31_amd64.deb
sha:6af464844158fd0ded016d6936addfc974714df8
-
alt-python38-tkinter_3.8.20-31_amd64.deb
sha:1ba28d64b074903888e746c15f9e2ffb9507fa87
-
alt-python38_3.8.20-31_arm64.deb
sha:5438d0c459919a3fd3a3e3aa0c2af23b7f7d7ca0
-
alt-python38-debug_3.8.20-31_arm64.deb
sha:542d862f95732e9fe471e8efc6e78eeab1bf5715
-
alt-python38-devel_3.8.20-31_arm64.deb
sha:47f63847b0022a4b9c8ab17ea497cf3834baa418
-
alt-python38-idle_3.8.20-31_arm64.deb
sha:fe2578fdbc7d17048a32165c3e01af9fea14e6ea
-
alt-python38-libs_3.8.20-31_arm64.deb
sha:371f52dff16de15e5c7195b9ba066e5dc481be6e
-
alt-python38-test_3.8.20-31_arm64.deb
sha:261bbac34ab54aa0ff1f85e3088149d15d7a0ec5
-
alt-python38-tkinter_3.8.20-31_arm64.deb
sha:8c60ab4a5cf6f68c9b6235db2c7e4349d7e149d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.