[CLSA-2026:1787935452] alt-python310-pip: Fix of CVE-2026-13346
Type:
security
Severity:
Moderate
Release date:
2026-08-28 16:44:23 UTC
Description:
- CVE-2026-13346: pip Link.filename double percent-decode allows path traversal via crafted package URL
CVEs fixed:
Updated packages:
  • alt-python310-pip-21.3.1-7.el9.noarch.rpm
    sha:e3ced2cf747563bcb449c76557823f9689767dc645524447b20009957f2c561e
  • alt-python310-pip-wheel-21.3.1-7.el9.noarch.rpm
    sha:58f99e6f602f5a7c0531a6b64fbc3fd611b4ba62f3f1da7fbf2944d2d82e57e8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.