[CLSA-2026:1784807030] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 11:44:28 UTC
Description:
* SECURITY UPDATE: reject control characters in imaplib IMAP4 commands - debian/patches/CVE-2025-15366.patch: guard IMAP4._command() - CVE-2025-15366 * SECURITY UPDATE: reject control characters in poplib POP3 commands - debian/patches/CVE-2025-15367.patch: guard POP3._putcmd() - CVE-2025-15367 * SECURITY UPDATE: control-character injection via http.cookies paths - debian/patches/CVE-2026-3644.patch: guard Morsel.update()/|=/unpickle/js_output - CVE-2026-3644 * SECURITY UPDATE: uncontrolled recursion in pyexpat content model - debian/patches/CVE-2026-4224.patch: recursion guard in conv_content_model() - CVE-2026-4224 * SECURITY UPDATE: webbrowser argument injection via leading-dash URL - debian/patches/CVE-2026-4519.patch: reject URLs starting with '-' - CVE-2026-4519
Updated packages:
  • alt-python310_3.10.20-3_amd64.deb
    sha:eb06f3f62accc7438fd342901cadc2c27efeca0a
  • alt-python310-debug_3.10.20-3_amd64.deb
    sha:10a4dec539b3445d8ec9edb7bd49bab82c98b189
  • alt-python310-devel_3.10.20-3_amd64.deb
    sha:e0542fed77ccb53631803ef1690d73f69c9e0492
  • alt-python310-idle_3.10.20-3_amd64.deb
    sha:bbd83ad10024ec6830dc1524486a1fbef701c058
  • alt-python310-libs_3.10.20-3_amd64.deb
    sha:6a8c89a113ed5c9319dbeb790123ad462be61193
  • alt-python310-test_3.10.20-3_amd64.deb
    sha:38e298e29803c22a8e8a4b8e50eaa7e3c7e02cd0
  • alt-python310-tkinter_3.10.20-3_amd64.deb
    sha:6a58eaf0686c1c073e21d201b36b40846ad9ebab
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.