Release date:
2026-08-20 11:37:08 UTC
Description:
- CVE-2023-5752: option injection via Mercurial revision passed as a bare argument
- CVE-2025-8869: arbitrary file write via unchecked symlink targets in tar extraction
- CVE-2026-1703: path traversal via sibling-prefix directory containment check
- CVE-2026-3219: archive format confusion for files matching both zip and tar signatures
- CVE-2026-8643: arbitrary file write via entry point name escaping the scripts directory
Updated packages:
-
alt-python36-pip-20.2.4-7.el10.noarch.rpm
sha:fd4abe61e5c915bd7a28379b97be89f822e4650ef7cbfdd53a2bb5adcba61315
-
alt-python36-pip-wheel-20.2.4-7.el10.noarch.rpm
sha:54f07dd2fdb04053aa0b25b60ffeb39b1810b988bfaac0dfdbf86242719b9d51
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.