[CLSA-2026:1790765282] alt-python314: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 10:48:15 UTC
Description:
- CVE-2026-15806: urllib: scope HTTPPasswordMgr credentials by URL scheme so https credentials are not sent over http. - CVE-2026-17084: stringprep: pin post-Unicode-3.2.0 case mappings in b3_exceptions so the idna codec follows RFC 3454.
Updated packages:
  • alt-python314-3.14.7-3.el9.x86_64.rpm
    sha:9c95da58fb41111198f0bd2b1b3a1735fe88e02f989e668c748a0506082db0ad
  • alt-python314-debug-3.14.7-3.el9.x86_64.rpm
    sha:23fac92bd59000b2394f551f08a7f8c895167f9ce185a9097c39b2880d31b007
  • alt-python314-devel-3.14.7-3.el9.x86_64.rpm
    sha:2f25ce534b6fc374346c1169143ae44452f9fffe84d38897e5c5c640e139f286
  • alt-python314-idle-3.14.7-3.el9.x86_64.rpm
    sha:fbd0504823bb7823cbae8d9051815ed79792cc9f952213dd3189f4d680241077
  • alt-python314-libs-3.14.7-3.el9.x86_64.rpm
    sha:176802f2808feb12ad365bd02da91c82a3f05ee1bf32050bd645551e40ce572e
  • alt-python314-test-3.14.7-3.el9.x86_64.rpm
    sha:cfbe935a4d6a3754f10a6c1e5cad6db4c211b9ecd3b57b958f11b25d599c3c60
  • alt-python314-tkinter-3.14.7-3.el9.x86_64.rpm
    sha:42fa4a3c5ea9689be6e75fa4bd1d48a6389856dc1f2626aaa1ea51d5b0dd3c7c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.