Release date:
2026-09-03 09:06:18 UTC
Description:
- CVE-2025-8869: symlink targets were not validated in the tarfile extraction fallback used on pythons without pep 706
- CVE-2026-1703: wheel extraction could write files into a sibling directory sharing a name prefix with the install directory
- CVE-2026-3219: a file that is both a tar and a zip archive was always treated as a zip, causing archive-type confusion
- CVE-2026-6357: the self version-update check ran after wheel install and could import a module planted by a just-installed wheel
- CVE-2026-8643: entry point script names were treated as paths, letting scripts be installed outside the scripts directory
- CVE-2026-13346: doubly-encoded package URL from an index could write files to arbitrary paths on download
Updated packages:
-
alt-python312-pip-23.3.1-4.el10.noarch.rpm
sha:546af3ab0a42e5bf4a2e8031b50e70f8f21013adb5e0c5a31983c6093ecad81f
-
alt-python312-pip-wheel-23.3.1-4.el10.noarch.rpm
sha:3546f22527e18fde0fe9e18a1d4f35fbf0269ac31d03939984dfe5e62de1284f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.