Release date:
2026-07-30 14:15:40 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always
accepted the standard-alphabet '+' and '/' characters even when an
alternative alphabet excluding them was specified via altchars, so
malformed input could bypass strict-alphabet validation filters
(CWE-704: incorrect type conversion or cast, per NVD).
- debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab
(gh-125346, PR gh-141128; adapted from the reviewed alt-python37
backport). Emits DeprecationWarning/FutureWarning when '+' or '/'
appear outside the alternative alphabet; decoded output unchanged.
- CVE-2025-12781
Updated packages:
-
alt-python39_3.9.23-23_amd64.deb
sha:8a4937c26c6eff1e2eb4a35a32d700b83526fb50
-
alt-python39-debug_3.9.23-23_amd64.deb
sha:513cc3e8a90c98c3b62588877ab7c27a67b525f8
-
alt-python39-devel_3.9.23-23_amd64.deb
sha:1789e66c475b226bcd880154b36a61635b160ab2
-
alt-python39-idle_3.9.23-23_amd64.deb
sha:485e967e7262d05bb2f0d9e3514875c20f738fdf
-
alt-python39-libs_3.9.23-23_amd64.deb
sha:874dac09034b6907565ca60f5ac189d057a1abf3
-
alt-python39-test_3.9.23-23_amd64.deb
sha:a7dc64e74e0183244b1aa8ddee7b88179f4a03c3
-
alt-python39-tkinter_3.9.23-23_amd64.deb
sha:90bbdc71df5558fe7825b46ab80a1f3d8c601ee7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.