[CLSA-2026:1790775334] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 13:35:47 UTC
Description:
- CVE-2026-15806: scope HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URI are no longer sent to the http:// URI of the same host; a URI registered without a scheme still matches any scheme (proxy authentication). - CVE-2026-17084: pin every codepoint that Unicode 14.0.0 case-folds but Unicode 3.2.0 does not to itself in stringprep's b3_exceptions table, so the idna codec follows RFC 3454; the table was regenerated with this version's own interpreter because it depends on the bundled UCD.
Updated packages:
  • alt-python311-3.11.16-4.el10.x86_64.rpm
    sha:ba02985ec6a78a2fb4c5311f4df718cda93c976dd9503446f42bda8b50dd75b1
  • alt-python311-debug-3.11.16-4.el10.x86_64.rpm
    sha:3414bbadccf22a19d03060a241faab82871046e7327ddb802d264c0e46a6233a
  • alt-python311-devel-3.11.16-4.el10.x86_64.rpm
    sha:20b93f1016eb234fc80eedcd801f96e84f37cb03db73758ad424c34953285995
  • alt-python311-idle-3.11.16-4.el10.x86_64.rpm
    sha:fa93a83ec5f936a4123c4f1d5fa6607ace8a6510e3432b41453e86fc73b2712a
  • alt-python311-libs-3.11.16-4.el10.x86_64.rpm
    sha:525fc548182a79b5cace0c7a11e3692c97ad1d5c58241e95055c4199e0f1a1f6
  • alt-python311-test-3.11.16-4.el10.x86_64.rpm
    sha:7bddf164f81f908eaf59d4826133061d28a9054345f2331047decb795f3fa6c6
  • alt-python311-tkinter-3.11.16-4.el10.x86_64.rpm
    sha:87a2db04f6b80234375198dc301b4e15943dbe3a454bc8c0e728c53536e31f73
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.