[CLSA-2026:1789554767] alt-python312: Fix of CVE-2026-6019
Type:
security
Severity:
Moderate
Release date:
2026-09-16 10:32:57 UTC
Description:
- CVE-2026-6019: percent-encode cookie values embedded in JavaScript by http.cookies.Morsel.js_output() and wrap them in decodeURIComponent(), so a value containing can no longer break out of the script context
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-5.el9.x86_64.rpm
    sha:4ca6baf2d579474e354b02dc0ada0fbdb8b15a27e121320124f8f04a0b588e7c
  • alt-python312-debug-3.12.14-5.el9.x86_64.rpm
    sha:f4cefff274db529713cad500f9824d950815f38952e908eabe171f453f996bd0
  • alt-python312-devel-3.12.14-5.el9.x86_64.rpm
    sha:55687b15d4fbe484118edfb7ab15432ce1af7c9be67c2c35c12bab1344e431d9
  • alt-python312-idle-3.12.14-5.el9.x86_64.rpm
    sha:4173e1942b2acaaddc34c1ff98e2a9bd8c579fbb9003a5a3a62eab44526762f3
  • alt-python312-libs-3.12.14-5.el9.x86_64.rpm
    sha:f8e62b32c8fd20dd4a0301c8245c23add72d6a3aacb1ad361a0063330131c0f2
  • alt-python312-test-3.12.14-5.el9.x86_64.rpm
    sha:3318a7b9a6380b97106b9c6e614ac11a4d335f9f4ae06833a41c02c759f33563
  • alt-python312-tkinter-3.12.14-5.el9.x86_64.rpm
    sha:61c02128205a2328a6a31afa0d4ec8c6ce1491818ea2ae104b883008b4909336
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.