[CLSA-2026:1784809370] alt-python310: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 12:23:26 UTC
Description:
- CVE-2025-15366: reject control characters in imaplib IMAP4 commands - CVE-2025-15367: reject control characters in poplib POP3 commands - CVE-2026-3644: reject control characters in http.cookies Morsel.update(), |=, unpickling and js_output - CVE-2026-4224: add recursion guard to pyexpat conv_content_model() to prevent C stack overflow - CVE-2026-4519: reject webbrowser URLs with a leading dash to prevent argument injection
Updated packages:
  • alt-python310-3.10.20-2.el8.x86_64.rpm
    sha:5ebfb99f5c1e8af12d1d24bd4d968258b0d0cfbeaa86de7cc497302d351446a2
  • alt-python310-debug-3.10.20-2.el8.x86_64.rpm
    sha:240aabb6ede70464920ed29743cf8f50bb523f0485c0f780bb1b66000149894b
  • alt-python310-devel-3.10.20-2.el8.x86_64.rpm
    sha:70fcf638771fe2d0f98c26a43a26a3ce4bb1dcec48441e0b018edb22f6018ea6
  • alt-python310-idle-3.10.20-2.el8.x86_64.rpm
    sha:31924cc6985fc91282aa5293c0f4645721737ca99483189a61f6b405b7553821
  • alt-python310-libs-3.10.20-2.el8.x86_64.rpm
    sha:f298ec3072b841d08ed9ddc2c9412256f5520927858a4c17262058171b9d343e
  • alt-python310-test-3.10.20-2.el8.x86_64.rpm
    sha:9abd98afe599061da42e21964284cede7cd9120804575d5b2ba05311eb6b5ada
  • alt-python310-tkinter-3.10.20-2.el8.x86_64.rpm
    sha:fd4a299efec836ea7f840b8e98c517780da528fee17f684723e00d414933f6c4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.