[CLSA-2026:1788436261] Fix CVE(s): CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-03 11:51:12 UTC
Description:
* SECURITY UPDATE: directory escape via Link.filename decoding the URL path twice - debian/patches/CVE-2026-13346.patch: decode the URL path once and reduce the file name to a single path component - CVE-2026-13346
CVEs fixed:
Updated packages:
  • alt-python36-pip_20.2.4-9_all.deb
    sha:d97b046cd975f0a4099b27849254c01c1cbfa758
  • alt-python36-pip-wheel_20.2.4-9_all.deb
    sha:08a273edf0a5ada80aade0c90f2c4d82cb118bb9
  • alt-python36-pip_20.2.4-9_all.deb
    sha:d97b046cd975f0a4099b27849254c01c1cbfa758
  • alt-python36-pip-wheel_20.2.4-9_all.deb
    sha:08a273edf0a5ada80aade0c90f2c4d82cb118bb9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.