[CLSA-2026:1784807431] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 11:51:08 UTC
Description:
* SECURITY UPDATE: reject control characters in imaplib IMAP4 commands - debian/patches/CVE-2025-15366.patch: guard IMAP4._command() - CVE-2025-15366 * SECURITY UPDATE: reject control characters in poplib POP3 commands - debian/patches/CVE-2025-15367.patch: guard POP3._putcmd() - CVE-2025-15367 * SECURITY UPDATE: control-character injection via http.cookies paths - debian/patches/CVE-2026-3644.patch: guard Morsel.update()/|=/unpickle/js_output - CVE-2026-3644 * SECURITY UPDATE: uncontrolled recursion in pyexpat content model - debian/patches/CVE-2026-4224.patch: recursion guard in conv_content_model() - CVE-2026-4224 * SECURITY UPDATE: webbrowser argument injection via leading-dash URL - debian/patches/CVE-2026-4519.patch: reject URLs starting with '-' - CVE-2026-4519
Updated packages:
  • alt-python310_3.10.20-3_amd64.deb
    sha:6c5fa3d2307e5c0489f6bf42e7464ee28512a5f5
  • alt-python310-debug_3.10.20-3_amd64.deb
    sha:4769cbf55cd244be6fc25cfbb86566e48ef992f1
  • alt-python310-devel_3.10.20-3_amd64.deb
    sha:55a57b486ac4397bcf60e1b88c90c0171fe755a8
  • alt-python310-idle_3.10.20-3_amd64.deb
    sha:ca50ccfbb82b1e501fa78f759afb922b9d4cffee
  • alt-python310-libs_3.10.20-3_amd64.deb
    sha:d4b2f31541e26beffdb165abfbec60ca322834c6
  • alt-python310-test_3.10.20-3_amd64.deb
    sha:48a4945cf72329d198b95d6b382df0d63239a7f1
  • alt-python310-tkinter_3.10.20-3_amd64.deb
    sha:a36dfe786908634dafc9bac205919b17a97af430
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.