[CLSA-2026:1787932336] alt-python310-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-08-28 17:41:07 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python310-pip-21.3.1-7.el7.noarch.rpm
    sha:1e91455c8af62851a2cdef57c728e3bbbd6ac1655a7b7a4cc33b25dd9fa23364
  • alt-python310-pip-wheel-21.3.1-7.el7.noarch.rpm
    sha:066e41aae49f475e8812b8a6d6694ef62af1c9774971b71b85ac3c20d1b91a89
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.