CLSA-2026-1776330599

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1776330599
Upstream
Published
2026-04-16T09:10:08Z
Modified
2026-06-01T00:32:22.483214644Z
Summary
python3.9: Fix of 11 CVEs
Details
  • CVE-2025-8291: fix zipfile ZIP64 EOCD Locator offset validation
  • CVE-2025-6069: fix quadratic complexity in HTMLParser
  • CVE-2025-4516: fix use-after-free in unicode-escape decoder with error handler
  • CVE-2026-2297: ensure SourcelessFileLoader uses io.open_code
  • CVE-2026-3479: reject invalid resource arguments in pkgutil.get_data()
  • CVE-2025-1795: fix email header list separator incorrectly encoded during folding
  • CVE-2026-0672: reject control characters in http cookies
  • CVE-2025-15282: reject control characters in data URL mediatypes
  • CVE-2026-3644: reject control characters in http.cookies.Morsel.update(), |=, unpickling, and js_output()
  • CVE-2026-4224: avoid unbound C recursion in convcontentmodel in pyexpat.c
  • CVE-2025-11468: preserve parens when folding email comments to prevent header injection
References

Affected packages

TuxCare:AlmaLinux:9.2
python-unversioned-command

Package

Name
python-unversioned-command
Purl
pkg:rpm/tuxcare/python-unversioned-command?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3

Package

Name
python3
Purl
pkg:rpm/tuxcare/python3?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3-debug

Package

Name
python3-debug
Purl
pkg:rpm/tuxcare/python3-debug?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3-devel

Package

Name
python3-devel
Purl
pkg:rpm/tuxcare/python3-devel?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3-idle

Package

Name
python3-idle
Purl
pkg:rpm/tuxcare/python3-idle?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3-libs

Package

Name
python3-libs
Purl
pkg:rpm/tuxcare/python3-libs?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3-test

Package

Name
python3-test
Purl
pkg:rpm/tuxcare/python3-test?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"
python3-tkinter

Package

Name
python3-tkinter
Purl
pkg:rpm/tuxcare/python3-tkinter?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.16-1.el9_2.2.tuxcare.els22

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776330599.json"