[CLSA-2026:1788428289] alt-python311-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-03 09:38:19 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python311-pip-21.3.1-6.el9.noarch.rpm
    sha:28881bee9144a6bebee27881003c416037de42e2c577355c7d78b7d6007512b3
  • alt-python311-pip-wheel-21.3.1-6.el9.noarch.rpm
    sha:1b07efb537e0bf89b99e249354b31abb942a53a9bc7524a700e206a3c6c4d06e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.