[CLSA-2026:1790787036] alt-python36: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 16:50:50 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme so https credentials are not sent over http. - CVE-2026-17084: pin post-Unicode-3.2.0 case mappings in stringprep's b3_exceptions so the idna codec follows RFC 3454.
Updated packages:
  • alt-python36-3.6.15-39.el10.x86_64.rpm
    sha:53d39bec7368dd55be0fdec4f69453d14f6d2a2caa96468107c4e5efad0bc264
  • alt-python36-debug-3.6.15-39.el10.x86_64.rpm
    sha:cd84d7eb1c40995356ae72b6c166494f3ba1e5bbaa5f0718362736ba92fc061b
  • alt-python36-devel-3.6.15-39.el10.x86_64.rpm
    sha:34d10145e3a00f6a510c09142efaa7f3c3a310d8e2a43d49f32acf643e699f0b
  • alt-python36-libs-3.6.15-39.el10.x86_64.rpm
    sha:91cbe315dbc6c53151c4c3bf170eac215844c04fe4aa8a718f4e50c69ed2dd3f
  • alt-python36-test-3.6.15-39.el10.x86_64.rpm
    sha:e8ba0a4bec472a5feccb833b3c792d828f3bb04a959acb2f6d82a30f28fe57bd
  • alt-python36-tkinter-3.6.15-39.el10.x86_64.rpm
    sha:33930ac965471e47c2f469ddc12f944eef8d036b602b0cce65ae001ae5d1c575
  • alt-python36-tools-3.6.15-39.el10.x86_64.rpm
    sha:389b1b091bf4c293f75b5bbd14fea428b14a1d9351d323a8d3a7ff1683fbff13
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.