[CLSA-2026:1790771565] alt-python313: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 12:32:58 UTC
Description:
- CVE-2026-15806: scope urllib.request HTTPPasswordMgr credentials by URL scheme so credentials registered for https:// are not sent over http://. - CVE-2026-17084: regenerate Lib/stringprep.py so the idna codec no longer applies case mappings from outside Unicode 3.2.0.
Updated packages:
  • alt-python313-3.13.15-5.el10.x86_64.rpm
    sha:a73668ec5578f17ece5e58637190371aabfb930f214cd1c779a435b18e9693c7
  • alt-python313-debug-3.13.15-5.el10.x86_64.rpm
    sha:09678c43b570ed32c4df2e72e045fff4ccf4f6d84bf730b5ffeac4feb2ca06f5
  • alt-python313-devel-3.13.15-5.el10.x86_64.rpm
    sha:200a63428a0a215848ae249cef618c8181c4553df42a39af36991c7be77ecfc5
  • alt-python313-idle-3.13.15-5.el10.x86_64.rpm
    sha:5bf574a5d8b4f557a5c0268e21bf3d5fc8c1b9f0de2bc0ecffa1ed897f6995fb
  • alt-python313-libs-3.13.15-5.el10.x86_64.rpm
    sha:aeaa18157da483266573a0175aebed7b092c63605498bd601ff5903bbb84d595
  • alt-python313-test-3.13.15-5.el10.x86_64.rpm
    sha:1d9505c90723e01612845f8eb6888f815564f76269e10040a4f947c4b501a7a2
  • alt-python313-tkinter-3.13.15-5.el10.x86_64.rpm
    sha:9d65b9a1014e7fe327ab20a50fbb7f482c0b53e288c99a818d3f80dc628eb124
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.