[CLSA-2026:1790779901] alt-python312: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-30 14:51:55 UTC
Description:
- CVE-2026-15806: scope urllib HTTPPasswordMgr credentials by URL scheme, so credentials registered for https:// are no longer sent to http://. - CVE-2026-17084: regenerate stringprep's b3_exceptions table so the idna codec no longer applies post-Unicode-3.2.0 case mappings.
Updated packages:
  • alt-python312-3.12.14-8.el9.x86_64.rpm
    sha:3c5f4c2a9073a82e55f9007b5320eb82efb3dfc3532eeac61e6bd035567313d9
  • alt-python312-debug-3.12.14-8.el9.x86_64.rpm
    sha:a4145b087a413c017bbf73dd1c12525f14e0fe2125d1693d016bd362dc5a6ecf
  • alt-python312-devel-3.12.14-8.el9.x86_64.rpm
    sha:48c3624fa6d0c69045bfc5eaf8af808498e26f3194df6a54232dd73715d89d16
  • alt-python312-idle-3.12.14-8.el9.x86_64.rpm
    sha:c3a76cf8dea301760af54fbe2798a28fa618e20acd0218da67502578880e542a
  • alt-python312-libs-3.12.14-8.el9.x86_64.rpm
    sha:15f85495485e0c0b7f7a51d5de32c067b30d9b8d6fb8cbdbdeb4c2918a346264
  • alt-python312-test-3.12.14-8.el9.x86_64.rpm
    sha:c6ba9ad862349e74346a47eee449abb64b9d2c1ff2656e1710cafc676ea2ec51
  • alt-python312-tkinter-3.12.14-8.el9.x86_64.rpm
    sha:9ee5d46a92e305d0fb6ff06c81f2baa880006fdbc1cdf03b4a2e85f2d397a19a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.