[CLSA-2026:1790779650] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 14:47:43 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr handed out credentials across URL schemes (CWE-523, unprotected transport of credentials). reduce_uri() reduces a URI to (authority, path) and drops the scheme, so add_password() and find_user_password() - and HTTPPasswordMgrWithPriorAuth update_authenticated()/is_authenticated() - treated "https://host/" and "http://host/" as the same URI. Credentials registered only for the TLS-protected origin were therefore sent in cleartext to an http:// URL reached through a downgrade or redirect. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them in the password managers; a URI registered without a scheme still matches any scheme, keeping proxy authentication working. Includes the upstream regression tests in Lib/test/test_urllib2.py. - CVE-2026-15806 * SECURITY UPDATE: stringprep (the "idna" codec, IDNA 2003) case-folded characters using post-Unicode-3.2.0 data. RFC 3454 mandates Unicode 3.2.0, but map_table_b3() falls back to str.lower() for any codepoint missing from the generated b3_exceptions table, and str.lower() uses the interpreter's bundled Unicode (12.1.0 here). Characters that gained a lowercase mapping later - Cherokee, Cyrillic Palochka, Georgian Mtavruli, Adlam, ... - were folded, so different Python versions derived different A-labels for the same U-label. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (gh-155292, GH-155293), which pins every such codepoint to itself in b3_exceptions, renames the 3.2.0 alias to unicodedata_320 and asserts the bundled unidata_version, plus the generator change in Tools/unicode/mkstringprep.py and the new idna test in Lib/test/test_codecs.py. The upstream table is specific to its UCD, so Lib/stringprep.py was regenerated with this version's own interpreter (UCD 12.1.0: 641 identity entries added). - CVE-2026-17084
Updated packages:
  • alt-python38_3.8.20-31_amd64.deb
    sha:7e9a7000f4e11c440fed25fac5d9f9023b8422e2
  • alt-python38-debug_3.8.20-31_amd64.deb
    sha:9c65b4551a540ca06e1d56fddf88dda629a68fb8
  • alt-python38-devel_3.8.20-31_amd64.deb
    sha:ff3fed71836a0e731937d5d180b52f7da994518a
  • alt-python38-idle_3.8.20-31_amd64.deb
    sha:8ddc3d7e89e0c7c7878ee671d7488efefec6211a
  • alt-python38-libs_3.8.20-31_amd64.deb
    sha:684aa7da24ef507e26ea08053ee19567ee411938
  • alt-python38-test_3.8.20-31_amd64.deb
    sha:6af464844158fd0ded016d6936addfc974714df8
  • alt-python38-tkinter_3.8.20-31_amd64.deb
    sha:1ba28d64b074903888e746c15f9e2ffb9507fa87
  • alt-python38_3.8.20-31_arm64.deb
    sha:5438d0c459919a3fd3a3e3aa0c2af23b7f7d7ca0
  • alt-python38-debug_3.8.20-31_arm64.deb
    sha:542d862f95732e9fe471e8efc6e78eeab1bf5715
  • alt-python38-devel_3.8.20-31_arm64.deb
    sha:47f63847b0022a4b9c8ab17ea497cf3834baa418
  • alt-python38-idle_3.8.20-31_arm64.deb
    sha:fe2578fdbc7d17048a32165c3e01af9fea14e6ea
  • alt-python38-libs_3.8.20-31_arm64.deb
    sha:371f52dff16de15e5c7195b9ba066e5dc481be6e
  • alt-python38-test_3.8.20-31_arm64.deb
    sha:261bbac34ab54aa0ff1f85e3088149d15d7a0ec5
  • alt-python38-tkinter_3.8.20-31_arm64.deb
    sha:8c60ab4a5cf6f68c9b6235db2c7e4349d7e149d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.