Release date:
2026-09-11 15:15:47 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
Updated packages:
-
alt-python39-pip-21.3.1-5.el9.noarch.rpm
sha:005b48da959f791c96f51fa7e5a3a672f825ed94d43eabeab38edbd1071e6a4d
-
alt-python39-pip-wheel-21.3.1-5.el9.noarch.rpm
sha:54f7bef50ae9fcb9a488442407a0e4063bb3879ff5e92883e22cc732e2e80342
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.