Release date:
2026-09-01 14:26:18 UTC
Description:
- CVE-2023-5752: option injection via Mercurial revision passed as a bare argument
- CVE-2025-8869: arbitrary file write via unchecked symlink targets in tar extraction
- CVE-2026-1703: path traversal via sibling-prefix directory containment check
- CVE-2026-3219: archive format confusion for files matching both zip and tar signatures
- CVE-2026-8643: arbitrary file write via entry point name escaping the scripts directory
- CVE-2026-13346: directory escape via Link.filename decoding the URL path twice
- CVE-2021-3572: revision hijacking via unicode separators in git references
Updated packages:
-
alt-python27-pip-20.2.4-6.el9.noarch.rpm
sha:d2301000ddb75083fa214f2f6b1bbad9d70bae56b44de0af5f57fa96b9acf6d1
-
alt-python27-pip-wheel-20.2.4-6.el9.noarch.rpm
sha:52e0063f72a776ad4057eb418f4d1a0959666ebaf7f2a1768b1b730d7fa6eb1d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.