[CLSA-2026:1787939073] alt-python310-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-08-28 17:44:58 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python310-pip-21.3.1-7.el8.noarch.rpm
    sha:af8d88f13f97b9ed1cdfbbc8a9b410901dd601ffd290422dd5cb8b9682c585e2
  • alt-python310-pip-wheel-21.3.1-7.el8.noarch.rpm
    sha:f0628901c5e48f3c17d18b96d34e3ce65c45d57639584a99dbadf42cabc13054
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.