[CLSA-2026:1789137535] Fix CVE(s): CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-11 14:39:05 UTC
Description:
* SECURITY UPDATE: path traversal via doubly percent-decoded package URLs - debian/patches/CVE-2026-13346.patch: decode the URL path only once so Link.filename cannot be tricked into producing a path separator - CVE-2026-13346
CVEs fixed:
Updated packages:
  • alt-python38-pip_22.2.1-6_all.deb
    sha:92a61b21b443fe1d90554f2ad8b9f4198854772a
  • alt-python38-pip-wheel_22.2.1-6_all.deb
    sha:a3e7386867294b94b5a27b759f4e792e802e34ff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.