[CLSA-2026:1785334679] alt-python39-pip: Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-29 14:18:17 UTC
Description:
- CVE-2023-5752: Mercurial revision option injection via VCS URL - CVE-2025-8869: tar extraction misses symlink target check (no PEP 706 fallback) - CVE-2026-1703: path traversal via os.path.commonprefix containment check - CVE-2026-3219: tar/ZIP polyglot archive interpretation conflict - CVE-2026-6357: post-install self-version check could import malicious wheel content - Restore el7 byte-compile path (regression from 21.3.1-3): double the backslashes in the __os_install_post sed capture group so the rewrite to the alt-python interpreter survives rpm macro expansion on el7
Updated packages:
  • alt-python39-pip-21.3.1-4.el7.noarch.rpm
    sha:761a170a0c925ca552aca396d443df768c7d2a03d6ccfce794d4b383f86a32c6
  • alt-python39-pip-wheel-21.3.1-4.el7.noarch.rpm
    sha:8cd02a8be8e2ae5d3520640b30374dd1795421c38eb697289220ef9f1f443f2f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.