[CLSA-2026:1788940263] alt-python313-setuptools: Fix of CVE-2026-59890
Type:
security
Severity:
Moderate
Release date:
2026-09-09 07:51:15 UTC
Description:
- CVE-2026-59890: normalize the Unicode form of both the MANIFEST.in pattern and the walked path before matching, so an exclude/global-exclude/ recursive-exclude/prune rule can no longer be bypassed by an NFC/NFD mismatch and leak the excluded file into the sdist
CVEs fixed:
Updated packages:
  • alt-python313-setuptools-69.0.2-5.el10.noarch.rpm
    sha:0fa7e53ca8aa95e05039b6a286cd53da7f56857dab7609aeb55233af6087c04a
  • alt-python313-setuptools-wheel-69.0.2-5.el10.noarch.rpm
    sha:a37d9164289eb3c2939682b9d211001af7636c82b046a2e5c9d85061ecdf8d92
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.