[CLSA-2026:1790770692] alt-python310: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 12:18:25 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URL are no longer sent to the same host over plain http://. - CVE-2026-17084: regenerate stringprep's b3_exceptions table (with this version's own UCD 13.0.0) so the idna codec no longer case-folds characters that Unicode 3.2.0 leaves alone.
Updated packages:
  • alt-python310-3.10.21-4.el7.x86_64.rpm
    sha:a4f16e29292651c78a6d764ac67cd705edc4428cd91b592084ef90a956a6505b
  • alt-python310-debug-3.10.21-4.el7.x86_64.rpm
    sha:a549a7565bd2517b613ee2f7b673b78a561ceaa8f666e46e1424101f3f23935d
  • alt-python310-devel-3.10.21-4.el7.x86_64.rpm
    sha:55fddab4a3192acff9a74ec3302c4a1a316b1ba97cb66eecf68c1089be8bdb11
  • alt-python310-idle-3.10.21-4.el7.x86_64.rpm
    sha:17264639eb734ba0522a432ba91f99cd718a07d832d10f6ba63bbe5219e58ee1
  • alt-python310-libs-3.10.21-4.el7.x86_64.rpm
    sha:8a9f935cff26d0d2b25fde137202ea14d5d9bf6919e45ffe527d753a9c9742d9
  • alt-python310-test-3.10.21-4.el7.x86_64.rpm
    sha:1665bc32e37e6ce8f4e4eff5b4afbc8f2aae95f388cfeaf9d18fec73e3db9bc3
  • alt-python310-tkinter-3.10.21-4.el7.x86_64.rpm
    sha:489d713e21f5fce64903d814ad7e53b4ac5547e90cbc7c323ff70fa4459cce80
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.