Release date:
2026-09-11 15:53:43 UTC
Description:
- CVE-2026-13346: pip Link.filename decoded doubly-encoded package URLs twice, allowing path traversal on install
Updated packages:
-
alt-python38-pip-22.2.1-6.el10.noarch.rpm
sha:f2d08d4cabc428a1b8ae9560612a46f21081170b59337da25b050fb38bc78bca
-
alt-python38-pip-wheel-22.2.1-6.el10.noarch.rpm
sha:e682714be10c884c95ded2034ba59398799a3f858e9460d081c86dce4920ac71
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.