Release date:
2026-09-11 14:51:12 UTC
Description:
* SECURITY UPDATE: path traversal via doubly percent-decoded package URLs
- debian/patches/CVE-2026-13346.patch: decode the URL path only once so
Link.filename cannot be tricked into producing a path separator
- CVE-2026-13346
Updated packages:
-
alt-python38-pip_22.2.1-6_all.deb
sha:6cd62d7fd8edfcf8363a627a330b5ab2cbfac96c
-
alt-python38-pip-wheel_22.2.1-6_all.deb
sha:ea93833ed4d18abaa41c9e2ec256936485304819
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.