[CLSA-2026:1790778436] alt-python310: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 14:27:30 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URL are no longer sent to the same host over plain http://. - CVE-2026-17084: regenerate stringprep's b3_exceptions table (with this version's own UCD 13.0.0) so the idna codec no longer case-folds characters that Unicode 3.2.0 leaves alone.
Updated packages:
  • alt-python310-3.10.21-4.el8.x86_64.rpm
    sha:1a009ef840f7ca123f1e971f4a4779a784849fd19b1897ea5fd781814b530e7c
  • alt-python310-debug-3.10.21-4.el8.x86_64.rpm
    sha:9e0e2648d091214dc08a8e47dfa3383f6a34af74dff24245beca22a8b3b79650
  • alt-python310-devel-3.10.21-4.el8.x86_64.rpm
    sha:1457d1e40e3f4b27bbec464754a244e7189aaf8b35df39468e006b79c7444212
  • alt-python310-idle-3.10.21-4.el8.x86_64.rpm
    sha:d4204ca6f9064899f176bd116197f7412333d3aae4bdaf311f580fcd76dc9689
  • alt-python310-libs-3.10.21-4.el8.x86_64.rpm
    sha:b4bc2500ce1c94bb94e30c39d5bb24ae19ed7991f9d664cda7a5dc6e0fb02b37
  • alt-python310-test-3.10.21-4.el8.x86_64.rpm
    sha:dfb2296ae16d045676fb2f02b1cd397d3cb62994ad55337469af645da8299d46
  • alt-python310-tkinter-3.10.21-4.el8.x86_64.rpm
    sha:9109388d66cddce2c10459c2689a561b500178fc41d74985413ba542683d5e68
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.