Release date:
2026-09-11 15:20:04 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
Updated packages:
-
alt-python39-pip-21.3.1-5.el8.noarch.rpm
sha:dc77ef39b69a2afc8400e51d578f91a5579f02d597f335bbaa823aaf4aa96ca4
-
alt-python39-pip-wheel-21.3.1-5.el8.noarch.rpm
sha:67673b7474406c5504988f5e94128e1c590c041e83e6245098ed3ffe6076fc43
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.