[CLSA-2026:1788440924] alt-python311-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-03 13:08:56 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python311-pip-21.3.1-6.el8.noarch.rpm
    sha:76317a10661a28bee5fb27a3ef83ce7b268b119ff689cc78c1ecd6053db28616
  • alt-python311-pip-wheel-21.3.1-6.el8.noarch.rpm
    sha:c77caefe75977722b1aeb80514493298b579ef108abb8c095c33da20d1826e7a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.