Release date:
2026-09-30 13:35:47 UTC
Description:
- CVE-2026-15806: scope HTTPPasswordMgr credentials by URL scheme, so
credentials registered for an https:// URI are no longer sent to the
http:// URI of the same host; a URI registered without a scheme still
matches any scheme (proxy authentication).
- CVE-2026-17084: pin every codepoint that Unicode 14.0.0 case-folds but
Unicode 3.2.0 does not to itself in stringprep's b3_exceptions table, so the
idna codec follows RFC 3454; the table was regenerated with this version's
own interpreter because it depends on the bundled UCD.
Updated packages:
-
alt-python311-3.11.16-4.el10.x86_64.rpm
sha:ba02985ec6a78a2fb4c5311f4df718cda93c976dd9503446f42bda8b50dd75b1
-
alt-python311-debug-3.11.16-4.el10.x86_64.rpm
sha:3414bbadccf22a19d03060a241faab82871046e7327ddb802d264c0e46a6233a
-
alt-python311-devel-3.11.16-4.el10.x86_64.rpm
sha:20b93f1016eb234fc80eedcd801f96e84f37cb03db73758ad424c34953285995
-
alt-python311-idle-3.11.16-4.el10.x86_64.rpm
sha:fa93a83ec5f936a4123c4f1d5fa6607ace8a6510e3432b41453e86fc73b2712a
-
alt-python311-libs-3.11.16-4.el10.x86_64.rpm
sha:525fc548182a79b5cace0c7a11e3692c97ad1d5c58241e95055c4199e0f1a1f6
-
alt-python311-test-3.11.16-4.el10.x86_64.rpm
sha:7bddf164f81f908eaf59d4826133061d28a9054345f2331047decb795f3fa6c6
-
alt-python311-tkinter-3.11.16-4.el10.x86_64.rpm
sha:87a2db04f6b80234375198dc301b4e15943dbe3a454bc8c0e728c53536e31f73
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.