Release date:
2026-07-30 14:41:05 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always
accepted the standard-alphabet '+' and '/' characters even when an
alternative alphabet excluding them was specified via altchars, so
malformed input could bypass strict-alphabet validation filters
(CWE-704: incorrect type conversion or cast, per NVD).
- debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab
(gh-125346, PR gh-141128; adapted from the reviewed alt-python37
backport). Emits DeprecationWarning/FutureWarning when '+' or '/'
appear outside the alternative alphabet; decoded output unchanged.
- CVE-2025-12781
Updated packages:
-
alt-python39_3.9.23-23_amd64.deb
sha:e771787822cac6b5af48b42147483996d5d82a7c
-
alt-python39-debug_3.9.23-23_amd64.deb
sha:3dc59b9d12eb66f8f28061f6d46bdb1264c89201
-
alt-python39-devel_3.9.23-23_amd64.deb
sha:12354c4bf5c5c6e9b1d3e6b4d1bb6d67c04b4da4
-
alt-python39-idle_3.9.23-23_amd64.deb
sha:c89cdac4e50cf213f63ad9f272ee02cf7c6a3281
-
alt-python39-libs_3.9.23-23_amd64.deb
sha:9ad5cfbd00eec61bb52b9f2b50abc062dbd594b9
-
alt-python39-test_3.9.23-23_amd64.deb
sha:ca89be97c4fd72c5e4c4c331c34380516b724cfc
-
alt-python39-tkinter_3.9.23-23_amd64.deb
sha:211d4ad86515349e76fb37a9df51e45c912247e6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.