[CLSA-2026:1777946712] python: Fix of CVE-2026-4519
Type:
security
Severity:
Important
Release date:
2026-05-05 02:05:16 UTC
Description:
- CVE-2026-4519: reject leading dashes in webbrowser URLs that could be treated as command-line options by external browsers; also close a %action-substitution bypass of the check in UnixBrowser.open()
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:f7acdc0e1109ca66350a247fe72ffb40842bf40b4c9aa4c687947fd9945d82a5
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:ce93b6812c7e29d64fe2f4b4abe862baf4b7bf4d909bad861d5a89965389cc95
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:cdca5e73e49798131b580cc40d33f7c0df1d9e346fd620cc8862db5abb0337ec
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els7.i686.rpm
    sha:b7cb506bec1d02d9629df01cfaf52b451f0e44ca6b5149d96723264e06e21372
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:ec0a5f821726792c50f64fe23436f2fdb1d97bed64995f022e8df92212342a21
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:e1dd3e15a38b7d876030593bfdf50786402aa25efebbd4a14bdff256dcacdcbd
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:7185aa31d62c3df1ee91f0369e6ff779f5094c23f0228fc1d824cf3a8ed926ef
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:d0c5af253f6871fa48173e5e50c241d7fd77bb1ffe0061b8923c20c9b7efea70
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.