[CLSA-2026:1789119565] Fix CVE(s): CVE-2026-59890
Type:
security
Severity:
Moderate
Release date:
2026-09-11 09:39:36 UTC
Description:
* SECURITY UPDATE: MANIFEST.in exclusion bypass via Unicode normalization - debian/patches/CVE-2026-59890.patch: normalize both the MANIFEST.in pattern and the walked path to NFC before matching, via a new unicode_utils.normalize() helper and a _NormalizedMatcher wrapper in translate_pattern(), so an exclude/global-exclude/recursive-exclude/ prune rule can no longer be bypassed by an NFC/NFD mismatch and leak the excluded file into the source distribution (CWE-176/CWE-697). - CVE-2026-59890
CVEs fixed:
Updated packages:
  • alt-python313-setuptools_69.0.2-4_all.deb
    sha:3b114274cef3a77911b9a47e8fb34240d1847a86
  • alt-python313-setuptools-wheel_69.0.2-4_all.deb
    sha:acb55d8a62300a2f9bd9271f0abfb0cfb6d2dadf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.