Release date:
2026-07-30 14:52:01 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always
accepted the standard-alphabet '+' and '/' characters even when an
alternative alphabet excluding them was specified via altchars, so
malformed input could bypass strict-alphabet validation filters
(CWE-704: incorrect type conversion or cast, per NVD).
- debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab
(gh-125346, PR gh-141128; adapted from the reviewed alt-python37
backport). Emits DeprecationWarning/FutureWarning when '+' or '/'
appear outside the alternative alphabet; decoded output unchanged.
- CVE-2025-12781
Updated packages:
-
alt-python39_3.9.23-23_amd64.deb
sha:85f052683bfd1187b04a32aff1efea2995c99bff
-
alt-python39-debug_3.9.23-23_amd64.deb
sha:3dc59b9d12eb66f8f28061f6d46bdb1264c89201
-
alt-python39-devel_3.9.23-23_amd64.deb
sha:b45fe87775dff98ab1918491958558254ded2bb7
-
alt-python39-idle_3.9.23-23_amd64.deb
sha:a58ec81711131b5a71763831a43267375c613527
-
alt-python39-libs_3.9.23-23_amd64.deb
sha:dc43efe06c2f98837a9bfb7e445275c6b9f1f1f6
-
alt-python39-test_3.9.23-23_amd64.deb
sha:10b579fa5c26ac5d81b0f97c704a824f5af37acc
-
alt-python39-tkinter_3.9.23-23_amd64.deb
sha:21918c270dd41e9aed28b1d360186a45f02b4911
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.