Release date:
2026-09-08 08:43:27 UTC
Description:
* SECURITY UPDATE: directory escape via Link.filename decoding the URL path twice
- debian/patches/CVE-2026-13346.patch: decode the URL path once and reduce the
file name to a single path component
- CVE-2026-13346
Updated packages:
-
alt-python37-pip_20.2.4-5_all.deb
sha:1eafa483f4c2df5a5008ba8a353185c75f520ba7
-
alt-python37-pip-wheel_20.2.4-5_all.deb
sha:a8abcccb8332ea3869bdfd5bbbb8acc613f7ba1e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.