Release date:
2026-07-23 09:50:38 UTC
Description:
* SECURITY UPDATE: reject control characters in imaplib IMAP4 commands
- debian/patches/CVE-2025-15366.patch: guard IMAP4._command()
- CVE-2025-15366
* SECURITY UPDATE: reject control characters in poplib POP3 commands
- debian/patches/CVE-2025-15367.patch: guard POP3._putcmd()
- CVE-2025-15367
* SECURITY UPDATE: control-character injection via http.cookies paths
- debian/patches/CVE-2026-3644.patch: guard Morsel.update()/|=/unpickle/js_output
- CVE-2026-3644
* SECURITY UPDATE: uncontrolled recursion in pyexpat content model
- debian/patches/CVE-2026-4224.patch: recursion guard in conv_content_model()
- CVE-2026-4224
* SECURITY UPDATE: webbrowser argument injection via leading-dash URL
- debian/patches/CVE-2026-4519.patch: reject URLs starting with '-'
- CVE-2026-4519
Updated packages:
-
alt-python310_3.10.20-3_amd64.deb
sha:ff4b4ada189f8c8ea9ccc12aaf6d7ae0f8225d66
-
alt-python310-debug_3.10.20-3_amd64.deb
sha:10a4dec539b3445d8ec9edb7bd49bab82c98b189
-
alt-python310-devel_3.10.20-3_amd64.deb
sha:f177ea9328af236de0f3691a72a114f54a5d2457
-
alt-python310-idle_3.10.20-3_amd64.deb
sha:f5c0588ea7b6241510aab47ec753a2769dcbbda4
-
alt-python310-libs_3.10.20-3_amd64.deb
sha:3d554826d45f2b423e4428fa57ce5fd04e7a4227
-
alt-python310-test_3.10.20-3_amd64.deb
sha:c38d94147117aefd16c57d1752569e885115ecf3
-
alt-python310-tkinter_3.10.20-3_amd64.deb
sha:798b7948d77f6bbef3cf2081f55f52aa8194d5b0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.