[CLSA-2026:1785171014] alt-python310-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 16:50:29 UTC
Description:
- CVE-2023-5752: Mercurial revision option injection in pip VCS URLs - CVE-2025-8869: symlink target not validated in tar extraction fallback - CVE-2026-1703: path traversal via os.path.commonprefix in is_within_directory - CVE-2026-3219: tar/ZIP polyglot archive type confusion in unpack_file - CVE-2026-6357: pip self-version check runs after install allowing module shadowing
Updated packages:
  • alt-python310-pip-21.3.1-6.el9.noarch.rpm
    sha:d1cfe57138acf35a74615ec10e1ffbf9c1c01244a7d0cf99046b651d69bd4a03
  • alt-python310-pip-wheel-21.3.1-6.el9.noarch.rpm
    sha:eb448a6dcc3948c6b13f3b860c25512a9ea0df81553a9cee1a52622b2d775256
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.