[CLSA-2026:1784800604] alt-python310: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 09:57:21 UTC
Description:
- CVE-2025-15366: reject control characters in imaplib IMAP4 commands - CVE-2025-15367: reject control characters in poplib POP3 commands - CVE-2026-3644: reject control characters in http.cookies Morsel.update(), |=, unpickling and js_output - CVE-2026-4224: add recursion guard to pyexpat conv_content_model() to prevent C stack overflow - CVE-2026-4519: reject webbrowser URLs with a leading dash to prevent argument injection
Updated packages:
  • alt-python310-3.10.20-2.el9.x86_64.rpm
    sha:ae4809de55a3f7a50466171f059fcb013693ee784963bded7de8c67ee694e0ab
  • alt-python310-debug-3.10.20-2.el9.x86_64.rpm
    sha:c003aa008c96b32fb0362a11696ecfe92610f8adbbf0c3eac0515a77e48eb79d
  • alt-python310-devel-3.10.20-2.el9.x86_64.rpm
    sha:f5e13f12d329a66a55ca59a452ce8f22ebb7e920e589389f1a64845d56418c22
  • alt-python310-idle-3.10.20-2.el9.x86_64.rpm
    sha:b8e64c25ebc0ce5c105a1cc8f4ecab00f9a3f3b1993cb8bd93b3c89d7e3fa288
  • alt-python310-libs-3.10.20-2.el9.x86_64.rpm
    sha:8280f02303a1438fa2fe47d18f7b6a296c14fc9f331a4f928521655829af5605
  • alt-python310-test-3.10.20-2.el9.x86_64.rpm
    sha:90680a907c6335b535124d9d1634b5b6e02329975c330ca3574ddf98b5d9d274
  • alt-python310-tkinter-3.10.20-2.el9.x86_64.rpm
    sha:ccad569859b784d6f4150d7f78941cafb7668dd61f4ee1c8205c3fb546234eee
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.