[CLSA-2026:1790760189] alt-python36: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 09:23:23 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme so https credentials are not sent over http. - CVE-2026-17084: pin post-Unicode-3.2.0 case mappings in stringprep's b3_exceptions so the idna codec follows RFC 3454.
Updated packages:
  • alt-python36-3.6.15-39.el7.x86_64.rpm
    sha:e11456bc36c949d17c37bb76ea8a462a85b3159dadb2e13f65f4f1b800bc4e81
  • alt-python36-debug-3.6.15-39.el7.x86_64.rpm
    sha:f42dc1653f7db2f385325bd6134a410f8d8cbd2a949ce62830e0fa3e2d070341
  • alt-python36-devel-3.6.15-39.el7.x86_64.rpm
    sha:1d30f9244b4b3be86cf5b603293b59875f78ed3958f18c2ba3766ecf0859427a
  • alt-python36-libs-3.6.15-39.el7.x86_64.rpm
    sha:cd6ae2b20c811a4a40c2eeddb1d4b4f4638bb50ffdb27db420358672a5c29fa8
  • alt-python36-test-3.6.15-39.el7.x86_64.rpm
    sha:5679776ea9f0e523828a486c0d5f637df1864242433274394d920cc59fc7f9c7
  • alt-python36-tkinter-3.6.15-39.el7.x86_64.rpm
    sha:ee10927dc6263185f50fa6879aa4d96bdfe226a5a799d34ceea5102028290d8a
  • alt-python36-tools-3.6.15-39.el7.x86_64.rpm
    sha:f1aed952b4522395b024d0dfc0e5ee30c5c625af224ed1d689e275a3a14c8d36
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.