[CLSA-2026:1777946871] python: Fix of CVE-2026-4519
Type:
security
Severity:
Important
Release date:
2026-05-05 02:07:56 UTC
Description:
- CVE-2026-4519: reject leading dashes in webbrowser URLs that could be treated as command-line options by external browsers; also close a %action-substitution bypass of the check in UnixBrowser.open()
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:3fada9af4d4ac40138e60b6baec9ff9d18ff2756568e4ee6d0cc6c6c67f979b5
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:efe6078ca1102fe4a839edb15612ec3a86bc10466acbeb4de8d6487690b8abdf
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:5d53664d6e178e9bde85f7cea3de65877f982ff8e0a7d7399994899922205356
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els7.i686.rpm
    sha:74e5ee5767f49939bd3ff3baaa98142cd694c755c168c8fefb039166425dcb25
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:5d1a3f1233d60f5229eb59404325af478ebb1479e61f928c0315ac4a28c21732
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:f938baf4e96ae430aa372ef01851f6ea50ea3ad2a2b67972d94acf9019f32352
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:30599075d6bf9efc7726247f8b3647b0ef34cc6b682b8aceacb350b9b24d4084
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els7.x86_64.rpm
    sha:ad89993f40280a8922602f3672918cd4e65437d39c9072655b54dcebd88311e4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.