[CLSA-2026:1790763584] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 11:36:35 UTC
Description:
- CVE-2026-15806: scope HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URI are no longer sent to the http:// URI of the same host; a URI registered without a scheme still matches any scheme (proxy authentication). - CVE-2026-17084: pin every codepoint that Unicode 14.0.0 case-folds but Unicode 3.2.0 does not to itself in stringprep's b3_exceptions table, so the idna codec follows RFC 3454; the table was regenerated with this version's own interpreter because it depends on the bundled UCD.
Updated packages:
  • alt-python311-3.11.16-4.el7.x86_64.rpm
    sha:e0cc0f264da943ec62a0b3930ff291a3a10b3b987dcea01a7f5cd35bff813c05
  • alt-python311-debug-3.11.16-4.el7.x86_64.rpm
    sha:8ae1a4a08f4a609c91089de1c111e1f12913f6cc3afeecb94fdc39dd4db615a7
  • alt-python311-devel-3.11.16-4.el7.x86_64.rpm
    sha:a3256b15744048536e24a018819cebb1c89bf425615bcc60e33b8e52a02369f0
  • alt-python311-idle-3.11.16-4.el7.x86_64.rpm
    sha:889f17d57bf720f46f0f77edf565556f55a3c604aa665d7635aa034881e3ff82
  • alt-python311-libs-3.11.16-4.el7.x86_64.rpm
    sha:b1ad76029af135f3a5307e93fa7ac5970bca9d8025dbf73a64c4774fc3c70215
  • alt-python311-test-3.11.16-4.el7.x86_64.rpm
    sha:f0693895d089f0ec3eaf1a7afcd4c259f40a52ea84f9cdaedde65404679a842d
  • alt-python311-tkinter-3.11.16-4.el7.x86_64.rpm
    sha:f2c2ced5f727ebdd686f7e8e9b32f4dbf174db09080ec128a393542ce0e15d63
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.