[CLSA-2026:1790753251] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 07:27:45 UTC
Description:
- CVE-2026-15806: scope HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URI are no longer sent to the http:// URI of the same host; a URI registered without a scheme still matches any scheme (proxy authentication). - CVE-2026-17084: pin every codepoint that Unicode 14.0.0 case-folds but Unicode 3.2.0 does not to itself in stringprep's b3_exceptions table, so the idna codec follows RFC 3454; the table was regenerated with this version's own interpreter because it depends on the bundled UCD.
Updated packages:
  • alt-python311-3.11.16-4.el9.x86_64.rpm
    sha:78d5bdb378d1d7f706abe0fcfc6dc11d4270c513ce4bef95f8eac88f4cb92283
  • alt-python311-debug-3.11.16-4.el9.x86_64.rpm
    sha:3960551b9ea0b2df29b46cd4abf161cac13ea0abe4d4571c2026e611eac4d21c
  • alt-python311-devel-3.11.16-4.el9.x86_64.rpm
    sha:74e7131eb8a36a1134ad445f46f270b629e9cc8eeaa0459805ffacde7f061fe7
  • alt-python311-idle-3.11.16-4.el9.x86_64.rpm
    sha:2586f8bb5e3c6a431abb6ecae24b2a8161c846716ee52290262e6b9c506227e6
  • alt-python311-libs-3.11.16-4.el9.x86_64.rpm
    sha:21a3b6344f96908f50c54bdf273105d09da3bfcab4a3f8a6568dcd23f7cbe63a
  • alt-python311-test-3.11.16-4.el9.x86_64.rpm
    sha:b82a145680771a7301a250c7658aca6408914519db3e43e674f3c690fe96e4c8
  • alt-python311-tkinter-3.11.16-4.el9.x86_64.rpm
    sha:5126613e600471839889d05c46ce476d854ab1cff1c4e2bf87ab8c0d3f68dc7a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.