[CLSA-2026:1790751989] alt-python27: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 07:06:42 UTC
Description:
- CVE-2026-15806: scope urllib2 HTTPPasswordMgr credentials by URL scheme so https credentials are not sent over http. - CVE-2026-17084: pin post-Unicode-3.2.0 case mappings in stringprep's b3_exceptions so the idna codec follows RFC 3454.
Updated packages:
  • alt-python27-2.7.18-44.el9.x86_64.rpm
    sha:e64197044dd72a49f235e4bacc67a24ec3a78056197d1b2d57eaea2ee46ea2c1
  • alt-python27-debug-2.7.18-44.el9.x86_64.rpm
    sha:39944d22da2c47998c9d5d03d743fc987843a0e7e93054c823c6bd23ebdfb1ab
  • alt-python27-devel-2.7.18-44.el9.x86_64.rpm
    sha:fe2b328a34b9e58af4d623d47d0c6f275a4c14cf09216dc5c3621def54397a55
  • alt-python27-libs-2.7.18-44.el9.x86_64.rpm
    sha:72b2d5004ba2d0be1a5381a1b731caa51999fdd6e55e89e52c8c40a53569accb
  • alt-python27-test-2.7.18-44.el9.x86_64.rpm
    sha:e67db99ab43baf3e3c4d359565e7771dbf6ed57c7f9896b98abe10b881fc0442
  • alt-python27-tkinter-2.7.18-44.el9.x86_64.rpm
    sha:76343a3b48a392cb8db7581833569bf1119c721694a3b6bb394811c0f4bd651b
  • alt-python27-tools-2.7.18-44.el9.x86_64.rpm
    sha:76349e0606f4a810a46c73d7dadb58c8ff08daceacebdadcc288c70f501df9a0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.