Release date:
2026-09-30 15:12:49 UTC
Description:
* SECURITY UPDATE: urllib.request HTTPPasswordMgr did not scope
credentials by URL scheme (CWE-523, unprotected transport of
credentials). reduce_uri() reduces a URI to an (authority, path) pair and
drops the scheme, so credentials registered for 'https://host/' were also
returned for 'http://host/'. An attacker able to force an HTTPS to HTTP
downgrade or redirect therefore received the Basic-auth credentials in
cleartext.
- debian/patches/CVE-2026-15806.patch: backport of cpython
a2773a34183b7d94a243bb98fd658926cc5348ce (gh-155694, GH-155696), which
adds _reduce_uri_with_scheme() and _is_suburi_with_scheme() and uses
them in HTTPPasswordMgr.add_password()/find_user_password() and
HTTPPasswordMgrWithPriorAuth.update_authenticated()/is_authenticated().
A URI registered without a scheme still matches any scheme, which keeps
proxy authentication working. Includes upstream's regression tests in
Lib/test/test_urllib2.py.
- CVE-2026-15806
* SECURITY UPDATE: stringprep (and so the 'idna' codec) applied case
mappings from outside Unicode 3.2.0, which RFC 3454 mandates.
map_table_b3() falls back to str.lower() for every codepoint not listed in
b3_exceptions, and str.lower() uses the interpreter's own Unicode 13.0.0
data, so characters that gained a lowercase mapping after 3.2.0
(Cherokee, Georgian Mtavruli, Adlam, Cyrillic Palochka and others) were
case-folded. Different Python versions derived different A-labels for the
same U-label, breaking domain-name comparison and enabling spoofing.
- debian/patches/CVE-2026-17084.patch: backport of cpython
1e54caa096678a38afcabecabb1ff72400dd6bae (cherry-pick of
7e109d084d55e7eb25837a5f3b47ef9beee547bc), which pins every such
codepoint to itself in b3_exceptions, renames the 3.2.0 database alias
to unicodedata_320 and asserts the generating unidata_version, plus the
matching Tools/unicode/mkstringprep.py and Lib/test/test_codecs.py
changes. The upstream table is specific to its Unicode database, so
Lib/stringprep.py was regenerated with this version's own 3.9.23
interpreter (UCD 13.0.0) rather than copied.
- CVE-2026-17084
Updated packages:
-
alt-python39_3.9.23-32_amd64.deb
sha:f3c8deb9c303bfbf6ad8a8c3969aa4774b9f49cc
-
alt-python39-debug_3.9.23-32_amd64.deb
sha:2377fa4b7144c42d7578b2829b8827abe70d369a
-
alt-python39-devel_3.9.23-32_amd64.deb
sha:534927e15a19fcbbb63dc8703137bc7b5a60866b
-
alt-python39-idle_3.9.23-32_amd64.deb
sha:afe1766cfd4d1dbccffedc051f9f561a82c5e495
-
alt-python39-libs_3.9.23-32_amd64.deb
sha:e202e7a9d0dc17eb396e951c476df2d697c56f63
-
alt-python39-test_3.9.23-32_amd64.deb
sha:1d8ad8756b05e917ba0c8fcaa3dd6a483832b164
-
alt-python39-tkinter_3.9.23-32_amd64.deb
sha:d10eab2691718569cccbf83efc4db557858d3a20
-
alt-python39_3.9.23-32_arm64.deb
sha:168ac012a395d46a5850f4ebe6df1482d47d0f40
-
alt-python39-debug_3.9.23-32_arm64.deb
sha:55bd3316cea665b84c126cfeeb89412d10018813
-
alt-python39-devel_3.9.23-32_arm64.deb
sha:5a97503910473a12e508489970227955ce7230db
-
alt-python39-idle_3.9.23-32_arm64.deb
sha:55ce5ce92a6f5df531a14b3afb5a8ead6605ef6a
-
alt-python39-libs_3.9.23-32_arm64.deb
sha:5de46d698c2a3afdb05affba29be13f94a48714d
-
alt-python39-test_3.9.23-32_arm64.deb
sha:954be0a50f67a093b1455a28d063b9172b4685df
-
alt-python39-tkinter_3.9.23-32_arm64.deb
sha:68172f091356db8f9a206bb879257cd24a821be7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.