[CLSA-2026:1789553755] alt-python312: Fix of CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-16 10:16:04 UTC
Description:
- CVE-2026-6019: percent-encode cookie values embedded in JavaScript by http.cookies.Morsel.js_output() and wrap them in decodeURIComponent(), so a value containing can no longer break out of the script context
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-5.el8.x86_64.rpm
    sha:24a2c42ea28cb50e5d78113dcedbf645effe56e13183fc6554a20f0709746aab
  • alt-python312-debug-3.12.14-5.el8.x86_64.rpm
    sha:a26d60f87d51b44d3a9d8517b39a7c15818734c6710c976af8d82188fab0687f
  • alt-python312-devel-3.12.14-5.el8.x86_64.rpm
    sha:0ce324cba192652b9519cedde2bcc4a348fc7a5c73184d614fb9925389014428
  • alt-python312-idle-3.12.14-5.el8.x86_64.rpm
    sha:4ee00991d843f9551479ca3571796d99b4199e8af7b880543c46e22825f607bb
  • alt-python312-libs-3.12.14-5.el8.x86_64.rpm
    sha:5fa36a5d31f22585c33cf4cb07b7bce42860c00685ba7840d91aefd9cc005cfa
  • alt-python312-test-3.12.14-5.el8.x86_64.rpm
    sha:d080018b3f8d6ef09f16e71c572b0ce4d7bb129c319998c8587f3b29cd090326
  • alt-python312-tkinter-3.12.14-5.el8.x86_64.rpm
    sha:b88812ceac4017abbc903beacbb6d314d1000f11c768e99c0b01115da4b78a47
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.