Release date:
2026-09-11 14:26:13 UTC
Description:
- CVE-2026-13346: pip Link.filename decoded doubly-encoded package URLs twice, allowing path traversal on install
Updated packages:
-
alt-python38-pip-22.2.1-6.el8.noarch.rpm
sha:a98121bb10dac3a95bd58373044a6497bc61f2a6069325b070e95ea21dd5effb
-
alt-python38-pip-wheel-22.2.1-6.el8.noarch.rpm
sha:de194f628e155fbddb2bd70c6843f375cbfe2e7575f991ae0ff4fb956e000bd8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.