Release date:
2026-09-03 14:21:19 UTC
Description:
* SECURITY UPDATE: pip Link.filename double percent-decode allows path traversal via crafted package URL
- debian/patches/CVE-2026-13346.patch: decode the URL path exactly once and join
the resulting file name onto the download directory as a single path component
- CVE-2026-13346
Updated packages:
-
alt-python310-pip_21.3.1-4_all.deb
sha:9c49aa23f9c0b3b4e219072b4e6cdd92b7f7ba0d
-
alt-python310-pip-wheel_21.3.1-4_all.deb
sha:0223858ee9f88339106e5f56bf1a97751c6c79bc
-
alt-python310-pip_21.3.1-4_all.deb
sha:9c49aa23f9c0b3b4e219072b4e6cdd92b7f7ba0d
-
alt-python310-pip-wheel_21.3.1-4_all.deb
sha:0223858ee9f88339106e5f56bf1a97751c6c79bc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.