[CLSA-2026:1776936971] Fix CVE(s): CVE-2026-4519
Type:
security
Severity:
Low
Release date:
2026-04-23 09:36:17 UTC
Description:
* SECURITY UPDATE: Command-line option injection in webbrowser.open() - debian/patches/CVE-2026-4519.patch: reject leading dashes in webbrowser.open() URLs to prevent command-line option injection in browser subprocesses - CVE-2026-4519
Updated packages:
  • alt-python37_3.7.17-15_amd64.deb
    sha:0e9dc58866ec6695d20c8a156223771a9eed0f0a
  • alt-python37-debug_3.7.17-15_amd64.deb
    sha:90bc55ce9c9362e9e1f6efce60d8a6e3d10c983e
  • alt-python37-devel_3.7.17-15_amd64.deb
    sha:1cceec3438d33d8996d0bd035a2823c4ae887cdc
  • alt-python37-libs_3.7.17-15_amd64.deb
    sha:67878de18b795a731df6342b52856da90b7633b1
  • alt-python37-test_3.7.17-15_amd64.deb
    sha:a2ee8ebc923145c8e2c58d7ed0f14a31dee76938
  • alt-python37-tkinter_3.7.17-15_amd64.deb
    sha:0bf154874f7c3f1ce5e1d1ca098909d5f54d094f
  • alt-python37-tools_3.7.17-15_amd64.deb
    sha:fc0a891e2cf980c3f2b21c986896ad4ed5bc1cc8
  • alt-python37_3.7.17-15_arm64.deb
    sha:0f66397219f00cf81267ec2557ed0e6f6ed7bfdb
  • alt-python37-debug_3.7.17-15_arm64.deb
    sha:c14d490d033a2cd49e6e946835661da437df2f1e
  • alt-python37-devel_3.7.17-15_arm64.deb
    sha:fb43ba103f48af24574edc5a985fce7fdc824226
  • alt-python37-libs_3.7.17-15_arm64.deb
    sha:6938150a45f3542e04986e7c2c7bc0bde9fc117d
  • alt-python37-test_3.7.17-15_arm64.deb
    sha:a9eeeeaa6b38d944ca3c8ca2e7420c7d8e8d25a0
  • alt-python37-tkinter_3.7.17-15_arm64.deb
    sha:11fdaebef7d5e2508b02562f02c1dc58ceb998ef
  • alt-python37-tools_3.7.17-15_arm64.deb
    sha:7ea3d49db329a76596fdcd8d4cd79d25c3fbfae6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.