[CLSA-2026:1787932512] alt-python310-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-08-29 10:51:24 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python310-pip-21.3.1-7.el10.noarch.rpm
    sha:c01086a39fda52d3c9775ff322975ac400976b3934858967047870f70d4e74e6
  • alt-python310-pip-wheel-21.3.1-7.el10.noarch.rpm
    sha:05b4ea5578d21de4cf78d03e24888f63a494fe263af3bb87372f18438953f32f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.