Release date:
2026-09-30 10:28:01 UTC
Description:
- CVE-2026-15806: scope HTTPPasswordMgr credentials by URL scheme, so
credentials registered for an https:// URI are no longer sent to the
http:// URI of the same host; a URI registered without a scheme still
matches any scheme (proxy authentication).
- CVE-2026-17084: pin every codepoint that Unicode 14.0.0 case-folds but
Unicode 3.2.0 does not to itself in stringprep's b3_exceptions table, so the
idna codec follows RFC 3454; the table was regenerated with this version's
own interpreter because it depends on the bundled UCD.
Updated packages:
-
alt-python311-3.11.16-4.el8.x86_64.rpm
sha:fdfa84ef256184e4c9340721481895680442813936a331dfaab97b073cb2567b
-
alt-python311-debug-3.11.16-4.el8.x86_64.rpm
sha:3780702962ff98400a1b33637a0cd34ab0032b0fccc01c6db5c607fcf2c7970b
-
alt-python311-devel-3.11.16-4.el8.x86_64.rpm
sha:ca6fd2f22369c290df4ca20784d7e377c16ab3608460c08443d265e3c15d716d
-
alt-python311-idle-3.11.16-4.el8.x86_64.rpm
sha:cfb00640e6928041ff854e0b0361a28992d7c79a2d77b75baf47e39dfd88ce7d
-
alt-python311-libs-3.11.16-4.el8.x86_64.rpm
sha:fadefab3e2c77c764f54e27f456e63ecb176646edef390ac8a495c4a8878893c
-
alt-python311-test-3.11.16-4.el8.x86_64.rpm
sha:1140dd77c91452412ea6ba6aa0934ad05af695a1a4dc1dd1f0b6111985290035
-
alt-python311-tkinter-3.11.16-4.el8.x86_64.rpm
sha:ad3e0c07d0d3f3feb18ca8475491ecd0ee7a9889d36c5e4ac13d5faa10b8307f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.