[CLSA-2026:1790784680] alt-python39: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 16:11:34 UTC
Description:
- CVE-2026-15806: scope urllib.request HTTPPasswordMgr credentials by URL scheme so credentials registered for https:// are not sent over http://. - CVE-2026-17084: regenerate Lib/stringprep.py so the idna codec no longer applies case mappings from outside Unicode 3.2.0.
Updated packages:
  • alt-python39-3.9.23-30.el7.x86_64.rpm
    sha:928c1908c06a355f77b2b4142f11726bae6dedb9b1a8bbf4a2095a39fa6287bf
  • alt-python39-debug-3.9.23-30.el7.x86_64.rpm
    sha:48fbe977199b774009f6ef703a54cf744a23272b08c3d57202016882e0d49c3a
  • alt-python39-devel-3.9.23-30.el7.x86_64.rpm
    sha:2cfae61a3222b35d0d4b46de164f29579f2ba8b489f08ebd32b8167f1e496430
  • alt-python39-idle-3.9.23-30.el7.x86_64.rpm
    sha:9b895761e68735994ebe85275c1186517cbd2a4c5881b1942852e9433f11fc86
  • alt-python39-libs-3.9.23-30.el7.x86_64.rpm
    sha:6d0c715b015c6220bc58d23a7f4352892e5c00109204a2f3996999368a5e7e0c
  • alt-python39-test-3.9.23-30.el7.x86_64.rpm
    sha:95c7755edfcc95d6e4074a36b0ab6f3d6a0dd5326b0031d28e73462c8add9bd2
  • alt-python39-tkinter-3.9.23-30.el7.x86_64.rpm
    sha:f35a580304989d2a31f115132a1bc65fca5662ec818185c4056203920a52c0c1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.