[CLSA-2026:1788342163] Fix CVE(s): CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-02 09:42:56 UTC
Description:
* SECURITY UPDATE: pip Link.filename double percent-decode allows path traversal via crafted package URL - debian/patches/CVE-2026-13346.patch: decode the URL path exactly once and join the resulting file name onto the download directory as a single path component - CVE-2026-13346
CVEs fixed:
Updated packages:
  • alt-python311-pip_21.3.1-5_all.deb
    sha:f4f9786f02867c1bab68ab3561c729f93cebc591
  • alt-python311-pip-wheel_21.3.1-5_all.deb
    sha:2cfbbd3197304dce13f8884f1803e5856bfa346a
  • alt-python311-pip_21.3.1-5_all.deb
    sha:f4f9786f02867c1bab68ab3561c729f93cebc591
  • alt-python311-pip-wheel_21.3.1-5_all.deb
    sha:2cfbbd3197304dce13f8884f1803e5856bfa346a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.