[CLSA-2026:1785176124] alt-python310-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 18:15:37 UTC
Description:
- CVE-2023-5752: Mercurial revision option injection in pip VCS URLs - CVE-2025-8869: symlink target not validated in tar extraction fallback - CVE-2026-1703: path traversal via os.path.commonprefix in is_within_directory - CVE-2026-3219: tar/ZIP polyglot archive type confusion in unpack_file - CVE-2026-6357: pip self-version check runs after install allowing module shadowing
Updated packages:
  • alt-python310-pip-21.3.1-6.el7.noarch.rpm
    sha:ab9d0507efeef7fa6302a7cebba3402ec04aab41a824fed5ebc733947d75f7b8
  • alt-python310-pip-wheel-21.3.1-6.el7.noarch.rpm
    sha:443b604033f7b9bd1432a067f8966d36ed2251ec1998d7ffbaadedde13209255
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.