Release date:
2026-09-30 11:36:35 UTC
Description:
- CVE-2026-15806: scope HTTPPasswordMgr credentials by URL scheme, so
credentials registered for an https:// URI are no longer sent to the
http:// URI of the same host; a URI registered without a scheme still
matches any scheme (proxy authentication).
- CVE-2026-17084: pin every codepoint that Unicode 14.0.0 case-folds but
Unicode 3.2.0 does not to itself in stringprep's b3_exceptions table, so the
idna codec follows RFC 3454; the table was regenerated with this version's
own interpreter because it depends on the bundled UCD.
Updated packages:
-
alt-python311-3.11.16-4.el7.x86_64.rpm
sha:e0cc0f264da943ec62a0b3930ff291a3a10b3b987dcea01a7f5cd35bff813c05
-
alt-python311-debug-3.11.16-4.el7.x86_64.rpm
sha:8ae1a4a08f4a609c91089de1c111e1f12913f6cc3afeecb94fdc39dd4db615a7
-
alt-python311-devel-3.11.16-4.el7.x86_64.rpm
sha:a3256b15744048536e24a018819cebb1c89bf425615bcc60e33b8e52a02369f0
-
alt-python311-idle-3.11.16-4.el7.x86_64.rpm
sha:889f17d57bf720f46f0f77edf565556f55a3c604aa665d7635aa034881e3ff82
-
alt-python311-libs-3.11.16-4.el7.x86_64.rpm
sha:b1ad76029af135f3a5307e93fa7ac5970bca9d8025dbf73a64c4774fc3c70215
-
alt-python311-test-3.11.16-4.el7.x86_64.rpm
sha:f0693895d089f0ec3eaf1a7afcd4c259f40a52ea84f9cdaedde65404679a842d
-
alt-python311-tkinter-3.11.16-4.el7.x86_64.rpm
sha:f2c2ced5f727ebdd686f7e8e9b32f4dbf174db09080ec128a393542ce0e15d63
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.