[CLSA-2026:1785420926] Fix CVE(s): CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:15:40 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). - debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab (gh-125346, PR gh-141128; adapted from the reviewed alt-python37 backport). Emits DeprecationWarning/FutureWarning when '+' or '/' appear outside the alternative alphabet; decoded output unchanged. - CVE-2025-12781
CVEs fixed:
Updated packages:
  • alt-python39_3.9.23-23_amd64.deb
    sha:8a4937c26c6eff1e2eb4a35a32d700b83526fb50
  • alt-python39-debug_3.9.23-23_amd64.deb
    sha:513cc3e8a90c98c3b62588877ab7c27a67b525f8
  • alt-python39-devel_3.9.23-23_amd64.deb
    sha:1789e66c475b226bcd880154b36a61635b160ab2
  • alt-python39-idle_3.9.23-23_amd64.deb
    sha:485e967e7262d05bb2f0d9e3514875c20f738fdf
  • alt-python39-libs_3.9.23-23_amd64.deb
    sha:874dac09034b6907565ca60f5ac189d057a1abf3
  • alt-python39-test_3.9.23-23_amd64.deb
    sha:a7dc64e74e0183244b1aa8ddee7b88179f4a03c3
  • alt-python39-tkinter_3.9.23-23_amd64.deb
    sha:90bbdc71df5558fe7825b46ab80a1f3d8c601ee7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.