Release date:
2026-07-24 13:36:42 UTC
Description:
- CVE-2025-15366: reject control characters in imaplib IMAP4 commands
- CVE-2025-15367: reject control characters in poplib POP3 commands
- CVE-2026-3644: reject control characters in http.cookies Morsel.update(), |=, unpickling and js_output
- CVE-2026-4224: add recursion guard to pyexpat conv_content_model() to prevent C stack overflow
- CVE-2026-4519: reject webbrowser URLs with a leading dash to prevent argument injection
Updated packages:
-
alt-python310-3.10.20-2.el10.x86_64.rpm
sha:65502e184bb95b3320a7eb1e3e910b42364e3a6920c0a2e00591096adecc77f2
-
alt-python310-debug-3.10.20-2.el10.x86_64.rpm
sha:06dfd4427887034deff5ca9d27962b596b15ce6745bfd7da0189da700c6c77b2
-
alt-python310-devel-3.10.20-2.el10.x86_64.rpm
sha:b017313d96187764af812762cab3899583b9955aa71b9f5a979d173d50634193
-
alt-python310-idle-3.10.20-2.el10.x86_64.rpm
sha:9ad4cf191c4b89d7f862b183076684ab6f87679210ce946ee1f21b97158c883a
-
alt-python310-libs-3.10.20-2.el10.x86_64.rpm
sha:8b4aaef02c4d60fafb941e2656c135fff517b4de9e0e4ef0d8cd5586f168382f
-
alt-python310-test-3.10.20-2.el10.x86_64.rpm
sha:d7d4b3fd6ebea313cfb7a026b14412081ba3e3aa5192cc2ee97ff5f4808e65d6
-
alt-python310-tkinter-3.10.20-2.el10.x86_64.rpm
sha:254b7c446b36cf65a8ad6b2828fe568fdf4a2525e0616640d90ecf4d6d7a865d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.