Release date:
2026-09-03 09:38:19 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
Updated packages:
-
alt-python311-pip-21.3.1-6.el9.noarch.rpm
sha:28881bee9144a6bebee27881003c416037de42e2c577355c7d78b7d6007512b3
-
alt-python311-pip-wheel-21.3.1-6.el9.noarch.rpm
sha:1b07efb537e0bf89b99e249354b31abb942a53a9bc7524a700e206a3c6c4d06e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.