[CLSA-2026:1788265326] alt-python314-pip: Fix of 6 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-01 12:22:21 UTC
Description:
- CVE-2026-13346: doubly-encoded package URL from an index could write files to arbitrary paths on download - CVE-2025-8869: tar extraction did not verify symlink members point inside the extraction directory - CVE-2026-1703: is_within_directory used commonprefix, allowing extraction to a sibling path sharing a name prefix; the containment check now compares resolved paths directly - CVE-2026-3219: concatenated tar and zip archives were always treated as zip; reject ambiguous archive signatures - CVE-2026-6357: self-version check imported modules after installing wheels; run the check before command execution - CVE-2026-8643: console_scripts and gui_scripts entry point names could install scripts outside the scripts directory
Updated packages:
  • alt-python314-pip-24.0-2.el10.noarch.rpm
    sha:4903d3fa6b1ede3df6b9ffae5d7147dbaee081970b7a7cc19a3cce265affc81c
  • alt-python314-pip-wheel-24.0-2.el10.noarch.rpm
    sha:1e324529a571c2e58479519db58c1f5f0e41e5f55e926366ea3de3ee276002ec
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.