[CLSA-2026:1790781156] Fix CVE(s): CVE-2026-15806, CVE-2026-17084
Type:
security
Severity:
Moderate
Release date:
2026-09-30 15:12:49 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr did not scope credentials by URL scheme (CWE-523, unprotected transport of credentials). reduce_uri() reduces a URI to an (authority, path) pair and drops the scheme, so credentials registered for 'https://host/' were also returned for 'http://host/'. An attacker able to force an HTTPS to HTTP downgrade or redirect therefore received the Basic-auth credentials in cleartext. - debian/patches/CVE-2026-15806.patch: backport of cpython a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses them in HTTPPasswordMgr.add_password()/find_user_password() and HTTPPasswordMgrWithPriorAuth.update_authenticated()/is_authenticated(). A URI registered without a scheme still matches any scheme, which keeps proxy authentication working. Includes upstream's regression tests in Lib/test/test_urllib2.py. - CVE-2026-15806 * SECURITY UPDATE: stringprep (and so the 'idna' codec) applied case mappings from outside Unicode 3.2.0, which RFC 3454 mandates. map_table_b3() falls back to str.lower() for every codepoint not listed in b3_exceptions, and str.lower() uses the interpreter's own Unicode 13.0.0 data, so characters that gained a lowercase mapping after 3.2.0 (Cherokee, Georgian Mtavruli, Adlam, Cyrillic Palochka and others) were case-folded. Different Python versions derived different A-labels for the same U-label, breaking domain-name comparison and enabling spoofing. - debian/patches/CVE-2026-17084.patch: backport of cpython 1e54caa096678a38afcabecabb1ff72400dd6bae (cherry-pick of 7e109d084d55e7eb25837a5f3b47ef9beee547bc), which pins every such codepoint to itself in b3_exceptions, renames the 3.2.0 database alias to unicodedata_320 and asserts the generating unidata_version, plus the matching Tools/unicode/mkstringprep.py and Lib/test/test_codecs.py changes. The upstream table is specific to its Unicode database, so Lib/stringprep.py was regenerated with this version's own 3.9.23 interpreter (UCD 13.0.0) rather than copied. - CVE-2026-17084
Updated packages:
  • alt-python39_3.9.23-32_amd64.deb
    sha:f3c8deb9c303bfbf6ad8a8c3969aa4774b9f49cc
  • alt-python39-debug_3.9.23-32_amd64.deb
    sha:2377fa4b7144c42d7578b2829b8827abe70d369a
  • alt-python39-devel_3.9.23-32_amd64.deb
    sha:534927e15a19fcbbb63dc8703137bc7b5a60866b
  • alt-python39-idle_3.9.23-32_amd64.deb
    sha:afe1766cfd4d1dbccffedc051f9f561a82c5e495
  • alt-python39-libs_3.9.23-32_amd64.deb
    sha:e202e7a9d0dc17eb396e951c476df2d697c56f63
  • alt-python39-test_3.9.23-32_amd64.deb
    sha:1d8ad8756b05e917ba0c8fcaa3dd6a483832b164
  • alt-python39-tkinter_3.9.23-32_amd64.deb
    sha:d10eab2691718569cccbf83efc4db557858d3a20
  • alt-python39_3.9.23-32_arm64.deb
    sha:168ac012a395d46a5850f4ebe6df1482d47d0f40
  • alt-python39-debug_3.9.23-32_arm64.deb
    sha:55bd3316cea665b84c126cfeeb89412d10018813
  • alt-python39-devel_3.9.23-32_arm64.deb
    sha:5a97503910473a12e508489970227955ce7230db
  • alt-python39-idle_3.9.23-32_arm64.deb
    sha:55ce5ce92a6f5df531a14b3afb5a8ead6605ef6a
  • alt-python39-libs_3.9.23-32_arm64.deb
    sha:5de46d698c2a3afdb05affba29be13f94a48714d
  • alt-python39-test_3.9.23-32_arm64.deb
    sha:954be0a50f67a093b1455a28d063b9172b4685df
  • alt-python39-tkinter_3.9.23-32_arm64.deb
    sha:68172f091356db8f9a206bb879257cd24a821be7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.