[CLSA-2026:1790784216] alt-python38: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 16:03:50 UTC
Description:
- CVE-2026-15806: scope urllib.request HTTPPasswordMgr credentials by URL scheme so https-only credentials are not sent over http (backport of cpython a2773a34183b, gh-155694). - CVE-2026-17084: pin post-Unicode-3.2.0 case mappings in stringprep's b3_exceptions, table regenerated for this version's UCD 12.1.0 (backport of cpython 1e54caa09667, gh-155292).
Updated packages:
  • alt-python38-3.8.20-29.el7.x86_64.rpm
    sha:6aa566f3af2b92caf7387a78d46f8c32a00ec730c9cad9e8dfb0bcd0015b1363
  • alt-python38-debug-3.8.20-29.el7.x86_64.rpm
    sha:fde81fba1053c1f8ee9b803d73233a6eed42aba3c907f18eb11c6a3f5583d2f2
  • alt-python38-devel-3.8.20-29.el7.x86_64.rpm
    sha:10c1f056f3ef7141fc9e96415d9d5c7350ebc88ecb1cc461676572764e100993
  • alt-python38-idle-3.8.20-29.el7.x86_64.rpm
    sha:7eb8e83ad72966b72f21c21a149a456553dfd17959f14420e47f40f1191b98b7
  • alt-python38-libs-3.8.20-29.el7.x86_64.rpm
    sha:43ce89285c7ed446835ce0f790ab88aa3d2e9558b3365c28ab96e3c291c348ac
  • alt-python38-test-3.8.20-29.el7.x86_64.rpm
    sha:ed944665f67afd9d5634bd9d7d041e70789d84ec4a22c38d2980d024a7d5d34d
  • alt-python38-tkinter-3.8.20-29.el7.x86_64.rpm
    sha:ac01af01dc1767a631ed03dafbb1e2ec2b59817572d2e8575d04b6d4a7f4df5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.