Release date:
2026-09-11 14:22:33 UTC
Description:
- CVE-2026-13346: pip Link.filename decoded doubly-encoded package URLs twice, allowing path traversal on install
Updated packages:
-
alt-python38-pip-22.2.1-6.el9.noarch.rpm
sha:ecbf9223cc92988fcada369839671c073145d648d5ba2499821fb1bf0e3dfca8
-
alt-python38-pip-wheel-22.2.1-6.el9.noarch.rpm
sha:d4f446225e1ad3b815d9487e896037a22c6ddb1c986037d4eda05300e5b51d40
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.