Release date:
2026-07-27 15:39:30 UTC
Description:
- CVE-2023-5752: Mercurial configuration injection via VCS URL revision option
- CVE-2025-8869: symlink targets not validated in fallback tar extraction
- CVE-2026-1703: path traversal via prefix matching when extracting archives
- CVE-2026-3219: concatenated tar/ZIP archives misinterpreted as ZIP
- CVE-2026-6357: self-version check could import modules from newly installed wheels
Updated packages:
-
alt-python38-pip-22.2.1-5.el8.noarch.rpm
sha:7c113128aa0a35b8e7d9fe04657088caf49e1ed37d8a137341f2a4546593adf8
-
alt-python38-pip-wheel-22.2.1-5.el8.noarch.rpm
sha:873a955d59fb169d561b72e73a4a0e65d4cf310b60e46106bac2f122c630e7c6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.