[CLSA-2026:1785166755] alt-python38-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 15:39:30 UTC
Description:
- CVE-2023-5752: Mercurial configuration injection via VCS URL revision option - CVE-2025-8869: symlink targets not validated in fallback tar extraction - CVE-2026-1703: path traversal via prefix matching when extracting archives - CVE-2026-3219: concatenated tar/ZIP archives misinterpreted as ZIP - CVE-2026-6357: self-version check could import modules from newly installed wheels
Updated packages:
  • alt-python38-pip-22.2.1-5.el8.noarch.rpm
    sha:7c113128aa0a35b8e7d9fe04657088caf49e1ed37d8a137341f2a4546593adf8
  • alt-python38-pip-wheel-22.2.1-5.el8.noarch.rpm
    sha:873a955d59fb169d561b72e73a4a0e65d4cf310b60e46106bac2f122c630e7c6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.