[CLSA-2026:1790755199] alt-python310: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 08:00:10 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme, so credentials registered for an https:// URL are no longer sent to the same host over plain http://. - CVE-2026-17084: regenerate stringprep's b3_exceptions table (with this version's own UCD 13.0.0) so the idna codec no longer case-folds characters that Unicode 3.2.0 leaves alone.
Updated packages:
  • alt-python310-3.10.21-4.el9.x86_64.rpm
    sha:ca8ed0b7d41d7d99b6ce39ee894c276891d2686fcfc7fe1db14c4a705d836628
  • alt-python310-debug-3.10.21-4.el9.x86_64.rpm
    sha:efd69a66f94e645e3987e3b1e124c9e8e62ddbe6e48879c2ca40addb8468a30e
  • alt-python310-devel-3.10.21-4.el9.x86_64.rpm
    sha:7e378a0e51935f16ad7c1b21850fcbc922c8935d59c741a391cefb6fad6186d9
  • alt-python310-idle-3.10.21-4.el9.x86_64.rpm
    sha:30ba339b88758b2bfb9e56a6c7d3039ddf4ffa6349c84d33056a54a583af0581
  • alt-python310-libs-3.10.21-4.el9.x86_64.rpm
    sha:9111fed8153b3eb697ca6ffbbafc4b5e108531fb104f3e21588263810b88743d
  • alt-python310-test-3.10.21-4.el9.x86_64.rpm
    sha:38e8f47dde17787ad74d0859253783d57cc7d5e1612d18663c0cc36d019637c9
  • alt-python310-tkinter-3.10.21-4.el9.x86_64.rpm
    sha:aba4f7c7488ee9e6361e507bf7055e380e16014470b1f4592d031b765b041a6f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.