[CLSA-2026:1778015238] python: Fix of CVE-2026-4519
Type:
security
Severity:
Important
Release date:
2026-05-05 23:32:54 UTC
Description:
- CVE-2026-4519: reject leading dashes in webbrowser URLs that could be treated as command-line options by external browsers; also close a %action-substitution bypass of the check in UnixBrowser.open()
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:6bd391b65e8a7a705d97d11283ab10c0741715c65f9b1e4995ad7afe795270c0
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:85509dd8d9606b4eca480d398f7a3eb2cde8d7ce9e778511e619633bf0c01cd8
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:64e9c7b1626ab44b472bb3013a1add83c2ed8b2cf0304873e32c0d7616453c7f
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els7.i686.rpm
    sha:e0d79895407ae5738a4c09f529776e1036503aa76a787b1fbf639e138d5f35e9
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:fd60afea44b142b29db9a663e2f6284712444fa6c3bdd987c1ae3f2f3b9f399a
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:8f5df215af82c42036f6d27a84eb531bf7e7bb07aa0de9b543cd3e97eb425e6e
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:ce93535cc038701a09562a48437cdb6956d37f283bbb993589124e4af57edfc0
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:da9e52d952f07189788c5feb2d5a17bbb0c8c96828d899e005fcb3c0ec43edf5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.