[CLSA-2026:1789140209] alt-python39-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-09-11 15:23:38 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python39-pip-21.3.1-5.el10.noarch.rpm
    sha:ea0ddb04737a8001a53dc6b335240d5f02ebc472733599c05b40eeff4e88f4e4
  • alt-python39-pip-wheel-21.3.1-5.el10.noarch.rpm
    sha:8ce9b181f5ef039f69a24622e7f28bb9339d258c5accc9b38c5dbfa37f8adfa4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.