[CLSA-2026:1790761487] alt-python39: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 09:44:59 UTC
Description:
- CVE-2026-15806: scope urllib.request HTTPPasswordMgr credentials by URL scheme so credentials registered for https:// are not sent over http://. - CVE-2026-17084: regenerate Lib/stringprep.py so the idna codec no longer applies case mappings from outside Unicode 3.2.0.
Updated packages:
  • alt-python39-3.9.23-30.el8.x86_64.rpm
    sha:0fe6c8385e3385b28e6eab70aad38d0b27a761d251880991f7e68530f63b6042
  • alt-python39-debug-3.9.23-30.el8.x86_64.rpm
    sha:aaa0c9f9d37d539ce7f9d317e5ca322b66a6b1d0a50e0254cce17975c7b1f484
  • alt-python39-devel-3.9.23-30.el8.x86_64.rpm
    sha:bdf75892df6158a69750a1001bde72a9dcdc2545843fc5b83090aff9b2bfc5ce
  • alt-python39-idle-3.9.23-30.el8.x86_64.rpm
    sha:ecfcb7b790ddd044baa1ac3a6bd3791d02b43a69b9491b2e6d6047a3265a7625
  • alt-python39-libs-3.9.23-30.el8.x86_64.rpm
    sha:a4a9b070b99c9e652eebce735d50e1de61fc027dd5888f06cb9ac35a3fecf7be
  • alt-python39-test-3.9.23-30.el8.x86_64.rpm
    sha:64ea44e567e939430116c056d74e952bb33b14cecdb9a6d35c3a3dcd5c16b372
  • alt-python39-tkinter-3.9.23-30.el8.x86_64.rpm
    sha:7859405bedf41f5b8cbf5e16a85134a96796691fa21ae19a42369e6ba6dc1f3a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.