[CLSA-2026:1788430685] alt-python311-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-03 10:18:14 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python311-pip-21.3.1-6.el7.noarch.rpm
    sha:424f07fde308e5efa11e07429a9e5a34ca54bb97da22d5315fd0aadccd90903f
  • alt-python311-pip-wheel-21.3.1-6.el7.noarch.rpm
    sha:0d2142fa81f019fcdbbe6aeb03589c904e00f09a98d8f91989bc1657661cf41d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.