[CLSA-2026:1790757273] alt-python310: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 08:34:44 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URL are no longer sent to the same host over plain http://. - CVE-2026-17084: regenerate stringprep's b3_exceptions table (with this version's own UCD 13.0.0) so the idna codec no longer case-folds characters that Unicode 3.2.0 leaves alone.
Updated packages:
  • alt-python310-3.10.21-4.el10.x86_64.rpm
    sha:6780feb503fe600e715c83f77dc3cb5b37c1195fbcc5756b04ad90c03a788978
  • alt-python310-debug-3.10.21-4.el10.x86_64.rpm
    sha:66fb688d52665cadc2c6cb941af3c52cf36cf91628cd718521e7aee7b2f41186
  • alt-python310-devel-3.10.21-4.el10.x86_64.rpm
    sha:0bc577237af03296f6a4e5e36079f3caff8075b0fadb3b1e5fede131cac4fa18
  • alt-python310-idle-3.10.21-4.el10.x86_64.rpm
    sha:233cbef6f81a3b18c1e615945c2949c24ff5740979c7d7c2fbe20b7b7c92a881
  • alt-python310-libs-3.10.21-4.el10.x86_64.rpm
    sha:304fbca5e7f41d68ec8a7a8e17d0d337ed4cdae81ed9dbce0241e4c3072a1f4e
  • alt-python310-test-3.10.21-4.el10.x86_64.rpm
    sha:d66a976af9e7ffd1ae679b9f986ed8fea3667f18cab6328f4dc47d5d32e383be
  • alt-python310-tkinter-3.10.21-4.el10.x86_64.rpm
    sha:bda2e6e28db0a8dbd6638a5c11bcbea3bcd554dd0b7b3d3c626b3c6962f0d653
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.