Release date:
2026-09-11 14:14:20 UTC
Description:
- CVE-2026-13346: pip Link.filename decoded doubly-encoded package URLs twice, allowing path traversal on install
Updated packages:
-
alt-python38-pip-22.2.1-6.el7.noarch.rpm
sha:733f9c9f79e5a96ea8911fe5bc06f4abac68ba17767c99a7f714f0200693551d
-
alt-python38-pip-wheel-22.2.1-6.el7.noarch.rpm
sha:7b1187b4fe774789018c238fa857e148218d367714f4f874f9eb87af46d88f3c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.