Release date:
2026-07-27 15:54:46 UTC
Description:
* SECURITY UPDATE: Mercurial revision option injection in pip VCS URLs
- debian/patches/CVE-2023-5752.patch: Mercurial revision option injection in pip VCS URLs
- CVE-2023-5752
* SECURITY UPDATE: symlink target not validated in tar extraction fallback
- debian/patches/CVE-2025-8869.patch: symlink target not validated in tar extraction fallback
- CVE-2025-8869
* SECURITY UPDATE: path traversal via os.path.commonprefix in is_within_directory
- debian/patches/CVE-2026-1703.patch: path traversal via os.path.commonprefix in is_within_directory
- CVE-2026-1703
* SECURITY UPDATE: tar/ZIP polyglot archive type confusion in unpack_file
- debian/patches/CVE-2026-3219.patch: tar/ZIP polyglot archive type confusion in unpack_file
- CVE-2026-3219
* SECURITY UPDATE: pip self-version check runs after install allowing module shadowing
- debian/patches/CVE-2026-6357.patch: pip self-version check runs after install allowing module shadowing
- CVE-2026-6357
Updated packages:
-
alt-python310-pip_21.3.1-3_all.deb
sha:090d44dcd3cb838db9ece8c0a15f8b1b36d80122
-
alt-python310-pip-wheel_21.3.1-3_all.deb
sha:67e860f557cb06085e557134361b204b8920c84d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.