Release date:
2026-09-09 09:01:33 UTC
Description:
- CVE-2026-59890: normalize the Unicode form of both the MANIFEST.in pattern
and the walked path before matching, so an exclude/global-exclude/
recursive-exclude/prune rule can no longer be bypassed by an NFC/NFD
mismatch and leak the excluded file into the sdist
Updated packages:
-
alt-python313-setuptools-69.0.2-5.el9.noarch.rpm
sha:912b362ca2961a1b17f6e4132fde3eb9b4e0ab6f2d20b5ce7eac3dcc6e7ad7fd
-
alt-python313-setuptools-wheel-69.0.2-5.el9.noarch.rpm
sha:d39a199c13cb3276ea7c54e4af98e9904430d83ce4e668d73c4e085876aa93ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.