Release date:
2026-07-23 12:23:26 UTC
Description:
- CVE-2025-15366: reject control characters in imaplib IMAP4 commands
- CVE-2025-15367: reject control characters in poplib POP3 commands
- CVE-2026-3644: reject control characters in http.cookies Morsel.update(), |=, unpickling and js_output
- CVE-2026-4224: add recursion guard to pyexpat conv_content_model() to prevent C stack overflow
- CVE-2026-4519: reject webbrowser URLs with a leading dash to prevent argument injection
Updated packages:
-
alt-python310-3.10.20-2.el8.x86_64.rpm
sha:5ebfb99f5c1e8af12d1d24bd4d968258b0d0cfbeaa86de7cc497302d351446a2
-
alt-python310-debug-3.10.20-2.el8.x86_64.rpm
sha:240aabb6ede70464920ed29743cf8f50bb523f0485c0f780bb1b66000149894b
-
alt-python310-devel-3.10.20-2.el8.x86_64.rpm
sha:70fcf638771fe2d0f98c26a43a26a3ce4bb1dcec48441e0b018edb22f6018ea6
-
alt-python310-idle-3.10.20-2.el8.x86_64.rpm
sha:31924cc6985fc91282aa5293c0f4645721737ca99483189a61f6b405b7553821
-
alt-python310-libs-3.10.20-2.el8.x86_64.rpm
sha:f298ec3072b841d08ed9ddc2c9412256f5520927858a4c17262058171b9d343e
-
alt-python310-test-3.10.20-2.el8.x86_64.rpm
sha:9abd98afe599061da42e21964284cede7cd9120804575d5b2ba05311eb6b5ada
-
alt-python310-tkinter-3.10.20-2.el8.x86_64.rpm
sha:fd4a299efec836ea7f840b8e98c517780da528fee17f684723e00d414933f6c4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.