[CLSA-2026:1784802977] alt-python310: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 10:36:55 UTC
Description:
- CVE-2025-15366: reject control characters in imaplib IMAP4 commands - CVE-2025-15367: reject control characters in poplib POP3 commands - CVE-2026-3644: reject control characters in http.cookies Morsel.update(), |=, unpickling and js_output - CVE-2026-4224: add recursion guard to pyexpat conv_content_model() to prevent C stack overflow - CVE-2026-4519: reject webbrowser URLs with a leading dash to prevent argument injection
Updated packages:
  • alt-python310-3.10.20-2.el7.x86_64.rpm
    sha:309571e1cd900c16ee5ba694fd0b890bba551bfb92c7a9366a3a999d192cf6c9
  • alt-python310-debug-3.10.20-2.el7.x86_64.rpm
    sha:c58b16083f7d778519483dc81fee298a1c783bf54bc8b695dc1268bcbb263f50
  • alt-python310-devel-3.10.20-2.el7.x86_64.rpm
    sha:55171c80f97477b31a90acfe5a4da5b1678b83a716a9b655dc1cae3f6c4f4c9c
  • alt-python310-idle-3.10.20-2.el7.x86_64.rpm
    sha:f310bace5e92e6681ade96a21036f7f18c47e72d72a0c76a7924bd0052eb5881
  • alt-python310-libs-3.10.20-2.el7.x86_64.rpm
    sha:9d6450b1eb024ac3311ef36965b7a9ee2553649dd8c5774e9d35fd27375f58c2
  • alt-python310-test-3.10.20-2.el7.x86_64.rpm
    sha:af3f99c0c84cb027a12caf914d8692a219000df64194801ff7eb8de8db823d95
  • alt-python310-tkinter-3.10.20-2.el7.x86_64.rpm
    sha:60afb45f99694110f0eba08939b98bdff3b725d3d7861327978783dc203e10f6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.