[CLSA-2026:1789484629] Fix CVE(s): CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-15 15:04:01 UTC
Description:
* SECURITY UPDATE: template injection in http.cookies.Morsel.js_output() - debian/patches/00477-CVE-2026-6019-cookies-js-output-injection.patch: percent-encode the cookie value with urllib.parse.quote() and wrap it in decodeURIComponent() instead of escaping only the double quote, so a value containing cannot break out of the script context (CWE-1336). - CVE-2026-6019
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-6_amd64.deb
    sha:a2245b227dcd88271a6ea4d41812ce9ac9195660
  • alt-python312-debug_3.12.14-6_amd64.deb
    sha:2a111e6424d59bce85cfde7c6ba787ed3f43be96
  • alt-python312-devel_3.12.14-6_amd64.deb
    sha:652a1b240b48ead7c443c28c76ddfe40dc8b1a31
  • alt-python312-idle_3.12.14-6_amd64.deb
    sha:dc8d172490f4a05749210551d2ac9ddd884c52da
  • alt-python312-libs_3.12.14-6_amd64.deb
    sha:037b90d97538bae80c7b4d903cef0f4535f481ae
  • alt-python312-test_3.12.14-6_amd64.deb
    sha:b940bb7275bbc0c09d26039b50f7ec458375b945
  • alt-python312-tkinter_3.12.14-6_amd64.deb
    sha:9353dd9f3586cdfca38319974762ddef50a32f62
  • alt-python312_3.12.14-6_arm64.deb
    sha:09a464872660fcb713023b633534e7810ead2302
  • alt-python312-debug_3.12.14-6_arm64.deb
    sha:9a1a0b0e3175060b51171e2a957cae589c9c0ea1
  • alt-python312-devel_3.12.14-6_arm64.deb
    sha:6b56018833ef3550c99e6bac45c3667f70ec88fb
  • alt-python312-idle_3.12.14-6_arm64.deb
    sha:e172be7aa4cac33574939f2a00ac9b0ec2258431
  • alt-python312-libs_3.12.14-6_arm64.deb
    sha:3cda85f37a4b1887421d2590309d6a0b6e96d73a
  • alt-python312-test_3.12.14-6_arm64.deb
    sha:d665aaf1e96a74f48ebddd337c4973cb54ca6e50
  • alt-python312-tkinter_3.12.14-6_arm64.deb
    sha:4bdd3ec3d67e5c2161820107d4a51bacd7039adc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.