[CLSA-2026:1785149838] alt-python36-setuptools: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-27 10:57:30 UTC
Description:
- CVE-2022-40897: regex denial of service via crafted HTML in package_index - CVE-2024-6345: remote code execution via command injection in VCS download functions - CVE-2025-47273: path traversal in PackageIndex download filename resolution
Updated packages:
  • alt-python36-setuptools-38.5.2-9.el7.noarch.rpm
    sha:b9c8e609eb62b3ec713510257e0b0c9ac3e328f9910dd5ebefe95e382340d0fe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.