Release date:
2026-09-02 07:03:03 UTC
Description:
- CVE-2026-13346: doubly-encoded package URL from an index could write files to arbitrary paths on download
- CVE-2025-8869: tar extraction did not verify symlink members point inside the extraction directory
- CVE-2026-1703: is_within_directory used commonprefix, allowing extraction to a sibling path sharing a name prefix; the containment check now compares resolved paths directly
- CVE-2026-3219: concatenated tar and zip archives were always treated as zip; reject ambiguous archive signatures
- CVE-2026-6357: self-version check imported modules after installing wheels; run the check before command execution
- CVE-2026-8643: console_scripts and gui_scripts entry point names could install scripts outside the scripts directory
Updated packages:
-
alt-python314-pip-24.0-2.el7.noarch.rpm
sha:d0632f15aaea9105b09caafdbbc8b0e562b3f1a2a9e914260f55b6a08d664092
-
alt-python314-pip-wheel-24.0-2.el7.noarch.rpm
sha:efb7c8a9429809e772db7508ad02f1de27f9b60bf96e9c1208bc99cb00edfa33
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.