Release date:
2026-07-27 18:05:29 UTC
Description:
* SECURITY UPDATE: Mercurial revision option injection via VCS URL
- debian/patches/CVE-2023-5752.patch: Mercurial revision option injection via VCS URL
- CVE-2023-5752
* SECURITY UPDATE: tar extraction misses symlink target check (no PEP 706 fallback)
- debian/patches/CVE-2025-8869.patch: tar extraction misses symlink target check (no PEP 706 fallback)
- CVE-2025-8869
* SECURITY UPDATE: path traversal via os.path.commonprefix containment check
- debian/patches/CVE-2026-1703.patch: path traversal via os.path.commonprefix containment check
- CVE-2026-1703
* SECURITY UPDATE: tar/ZIP polyglot archive interpretation conflict
- debian/patches/CVE-2026-3219.patch: tar/ZIP polyglot archive interpretation conflict
- CVE-2026-3219
* SECURITY UPDATE: post-install self-version check could import malicious wheel content
- debian/patches/CVE-2026-6357.patch: post-install self-version check could import malicious wheel content
- CVE-2026-6357
Updated packages:
-
alt-python39-pip_21.3.1-3_all.deb
sha:38d4c67e04f81fabd9aff424b9ef2be8f0f4f26c
-
alt-python39-pip-wheel_21.3.1-3_all.deb
sha:0e330437401a87c33ba6b5ac67a148054352e8f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.