Release date:
2026-07-30 14:46:48 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always
accepted the standard-alphabet '+' and '/' characters even when an
alternative alphabet excluding them was specified via altchars, so
malformed input could bypass strict-alphabet validation filters
(CWE-704: incorrect type conversion or cast, per NVD).
- debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab
(gh-125346, PR gh-141128; adapted from the reviewed alt-python37
backport). Emits DeprecationWarning/FutureWarning when '+' or '/'
appear outside the alternative alphabet; decoded output unchanged.
- CVE-2025-12781
Updated packages:
-
alt-python39_3.9.23-23_amd64.deb
sha:414b6c4bdf114c6d89d8973e3ce7dabf402b627a
-
alt-python39-debug_3.9.23-23_amd64.deb
sha:8c6a65c56e8e250a9d0c24b31fcfc87e0cb37612
-
alt-python39-devel_3.9.23-23_amd64.deb
sha:25b66f624b4c2e02c9443f6d724a07848e206944
-
alt-python39-idle_3.9.23-23_amd64.deb
sha:eb4d7192c2aaca1d72adba93bc2cab7da79a79b4
-
alt-python39-libs_3.9.23-23_amd64.deb
sha:54c80449fb15958f5cd9fed6d15b0517645e9921
-
alt-python39-test_3.9.23-23_amd64.deb
sha:bb84d5adb5f841eb9a3f78702be78ba7cc37c52b
-
alt-python39-tkinter_3.9.23-23_amd64.deb
sha:227fac54aaab45ed08802386a0dfdf342015b6fa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.