{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-2297: importlib: route sourceless imports through io.open_code();\n  FileLoader.get_data() only special-cased SourceLoader and\n  ExtensionFileLoader, so loading a legacy .pyc via SourcelessFileLoader\n  used a plain file object and never raised the 'open_code' audit event,\n  leaving audit hooks unable to observe or veto the read\n- CVE-2026-6879: xml.etree: cache the sibling lookup in ElementPath\n  positional predicates; the previous code rebuilt the parent's child list\n  once per candidate element, making expressions such as './/tag[last()]'\n  quadratic in the number of matches and giving an attacker-supplied\n  document a CPU denial-of-service lever\n- CVE-2025-12781: base64: warn when b64decode() or urlsafe_b64decode() is\n  given data containing the standard '+' or '/' characters while an\n  alternative alphabet is in use, since those characters are silently\n  reinterpreted rather than rejected; a malformed altchars now raises\n  ValueError instead of tripping an assertion that vanishes under -O",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
        "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_python/el10/advisories/2026/clsa-2026_1788171032.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-31T10:11:51Z",
      "generator": {
        "date": "2026-08-31T10:11:51Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788171032",
      "initial_release_date": "2026-08-31T10:11:51Z",
      "revision_history": [
        {
          "date": "2026-08-31T10:11:51Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "alt-python38: Fix of 8 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 10",
                "product": {
                  "name": "Community Enterprise Operating System 10",
                  "product_id": "CentOS-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-python38-0:3.8.20-25.el10.x86_64",
                "product": {
                  "name": "alt-python38-0:3.8.20-25.el10.x86_64",
                  "product_id": "alt-python38-0:3.8.20-25.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-python38@3.8.20-25.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python38-devel-0:3.8.20-25.el10.x86_64",
                "product": {
                  "name": "alt-python38-devel-0:3.8.20-25.el10.x86_64",
                  "product_id": "alt-python38-devel-0:3.8.20-25.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-python38-devel@3.8.20-25.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python38-idle-0:3.8.20-25.el10.x86_64",
                "product": {
                  "name": "alt-python38-idle-0:3.8.20-25.el10.x86_64",
                  "product_id": "alt-python38-idle-0:3.8.20-25.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-python38-idle@3.8.20-25.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python38-tkinter-0:3.8.20-25.el10.x86_64",
                "product": {
                  "name": "alt-python38-tkinter-0:3.8.20-25.el10.x86_64",
                  "product_id": "alt-python38-tkinter-0:3.8.20-25.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-python38-tkinter@3.8.20-25.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python38-test-0:3.8.20-25.el10.x86_64",
                "product": {
                  "name": "alt-python38-test-0:3.8.20-25.el10.x86_64",
                  "product_id": "alt-python38-test-0:3.8.20-25.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-python38-test@3.8.20-25.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python38-libs-0:3.8.20-25.el10.x86_64",
                "product": {
                  "name": "alt-python38-libs-0:3.8.20-25.el10.x86_64",
                  "product_id": "alt-python38-libs-0:3.8.20-25.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-python38-libs@3.8.20-25.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python38-0:3.8.20-25.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64"
        },
        "product_reference": "alt-python38-0:3.8.20-25.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python38-devel-0:3.8.20-25.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64"
        },
        "product_reference": "alt-python38-devel-0:3.8.20-25.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python38-idle-0:3.8.20-25.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64"
        },
        "product_reference": "alt-python38-idle-0:3.8.20-25.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python38-tkinter-0:3.8.20-25.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        },
        "product_reference": "alt-python38-tkinter-0:3.8.20-25.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python38-test-0:3.8.20-25.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64"
        },
        "product_reference": "alt-python38-test-0:3.8.20-25.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python38-libs-0:3.8.20-25.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64"
        },
        "product_reference": "alt-python38-libs-0:3.8.20-25.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2022-48565",
      "cwe": {
        "id": "CWE-611",
        "name": "Improper Restriction of XML External Entity Reference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48565"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue42051",
          "url": "https://bugs.python.org/issue42051"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231006-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20231006-0007/"
        }
      ],
      "release_date": "2023-08-22T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-6100",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.\n\nThe vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e",
          "url": "https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d",
          "url": "https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2",
          "url": "https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20",
          "url": "https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b",
          "url": "https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3",
          "url": "https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/148395",
          "url": "https://github.com/python/cpython/issues/148395"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/148396",
          "url": "https://github.com/python/cpython/pull/148396"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/13/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/13/10"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10117",
          "url": "https://access.redhat.com/errata/RHSA-2026:10117"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10140",
          "url": "https://access.redhat.com/errata/RHSA-2026:10140"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10141",
          "url": "https://access.redhat.com/errata/RHSA-2026:10141"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10711",
          "url": "https://access.redhat.com/errata/RHSA-2026:10711"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10745",
          "url": "https://access.redhat.com/errata/RHSA-2026:10745"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10774",
          "url": "https://access.redhat.com/errata/RHSA-2026:10774"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10949",
          "url": "https://access.redhat.com/errata/RHSA-2026:10949"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10950",
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11062",
          "url": "https://access.redhat.com/errata/RHSA-2026:11062"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11077",
          "url": "https://access.redhat.com/errata/RHSA-2026:11077"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11768",
          "url": "https://access.redhat.com/errata/RHSA-2026:11768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13692",
          "url": "https://access.redhat.com/errata/RHSA-2026:13692"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13812",
          "url": "https://access.redhat.com/errata/RHSA-2026:13812"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14652",
          "url": "https://access.redhat.com/errata/RHSA-2026:14652"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14653",
          "url": "https://access.redhat.com/errata/RHSA-2026:14653"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14656",
          "url": "https://access.redhat.com/errata/RHSA-2026:14656"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16699",
          "url": "https://access.redhat.com/errata/RHSA-2026:16699"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17525",
          "url": "https://access.redhat.com/errata/RHSA-2026:17525"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17619",
          "url": "https://access.redhat.com/errata/RHSA-2026:17619"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19019",
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19064",
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19175",
          "url": "https://access.redhat.com/errata/RHSA-2026:19175"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19176",
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19177",
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19216",
          "url": "https://access.redhat.com/errata/RHSA-2026:19216"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19549",
          "url": "https://access.redhat.com/errata/RHSA-2026:19549"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19570",
          "url": "https://access.redhat.com/errata/RHSA-2026:19570"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19571",
          "url": "https://access.redhat.com/errata/RHSA-2026:19571"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19576",
          "url": "https://access.redhat.com/errata/RHSA-2026:19576"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19590",
          "url": "https://access.redhat.com/errata/RHSA-2026:19590"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21275",
          "url": "https://access.redhat.com/errata/RHSA-2026:21275"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21682",
          "url": "https://access.redhat.com/errata/RHSA-2026:21682"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:25096",
          "url": "https://access.redhat.com/errata/RHSA-2026:25096"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26187",
          "url": "https://access.redhat.com/errata/RHSA-2026:26187"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30078",
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30087",
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30088",
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30089",
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:52400",
          "url": "https://access.redhat.com/errata/RHSA-2026:52400"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8822",
          "url": "https://access.redhat.com/errata/RHSA-2026:8822"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8824",
          "url": "https://access.redhat.com/errata/RHSA-2026:8824"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9228",
          "url": "https://access.redhat.com/errata/RHSA-2026:9228"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-6100",
          "url": "https://access.redhat.com/security/cve/CVE-2026-6100"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json"
        }
      ],
      "release_date": "2026-04-13T18:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2022-37454",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-37454"
        },
        {
          "category": "external",
          "summary": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
          "url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
        },
        {
          "category": "external",
          "summary": "https://eprint.iacr.org/2023/331",
          "url": "https://eprint.iacr.org/2023/331"
        },
        {
          "category": "external",
          "summary": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
          "url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
        },
        {
          "category": "external",
          "summary": "https://mouha.be/sha-3-buffer-overflow/",
          "url": "https://mouha.be/sha-3-buffer-overflow/"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=33281106",
          "url": "https://news.ycombinator.com/item?id=33281106"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=35050307",
          "url": "https://news.ycombinator.com/item?id=35050307"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202305-02",
          "url": "https://security.gentoo.org/glsa/202305-02"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2022/dsa-5267",
          "url": "https://www.debian.org/security/2022/dsa-5267"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2022/dsa-5269",
          "url": "https://www.debian.org/security/2022/dsa-5269"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230203-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20230203-0001/"
        }
      ],
      "release_date": "2022-10-21T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2020-27619",
      "notes": [
        {
          "category": "description",
          "text": "In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue41944",
          "url": "https://bugs.python.org/issue41944"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8",
          "url": "https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9",
          "url": "https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33",
          "url": "https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794",
          "url": "https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b",
          "url": "https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202402-04",
          "url": "https://security.gentoo.org/glsa/202402-04"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20201123-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20201123-0004/"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujul2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        }
      ],
      "release_date": "2020-10-22T03:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2007-4559",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2007-4559"
        },
        {
          "category": "external",
          "summary": "http://mail.python.org/pipermail/python-dev/2007-August/074290.html",
          "url": "http://mail.python.org/pipermail/python-dev/2007-August/074290.html"
        },
        {
          "category": "external",
          "summary": "http://mail.python.org/pipermail/python-dev/2007-August/074292.html",
          "url": "http://mail.python.org/pipermail/python-dev/2007-August/074292.html"
        },
        {
          "category": "external",
          "summary": "http://secunia.com/advisories/26623",
          "url": "http://secunia.com/advisories/26623"
        },
        {
          "category": "external",
          "summary": "http://www.vupen.com/english/advisories/2007/3022",
          "url": "http://www.vupen.com/english/advisories/2007/3022"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=263261",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=263261"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202309-06",
          "url": "https://security.gentoo.org/glsa/202309-06"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"
        }
      ],
      "release_date": "2007-08-28T01:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-4517",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f",
          "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da",
          "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9",
          "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a",
          "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e",
          "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a",
          "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a",
          "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01",
          "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1",
          "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/135034",
          "url": "https://github.com/python/cpython/issues/135034"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/135037",
          "url": "https://github.com/python/cpython/pull/135037"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
        }
      ],
      "release_date": "2025-06-03T13:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2021-29921",
      "notes": [
        {
          "category": "description",
          "text": "In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-29921"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue36384",
          "url": "https://bugs.python.org/issue36384"
        },
        {
          "category": "external",
          "summary": "https://docs.python.org/3/library/ipaddress.html",
          "url": "https://docs.python.org/3/library/ipaddress.html"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rst",
          "url": "https://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rst"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/12577",
          "url": "https://github.com/python/cpython/pull/12577"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/25099",
          "url": "https://github.com/python/cpython/pull/25099"
        },
        {
          "category": "external",
          "summary": "https://github.com/sickcodes",
          "url": "https://github.com/sickcodes"
        },
        {
          "category": "external",
          "summary": "https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.md",
          "url": "https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.md"
        },
        {
          "category": "external",
          "summary": "https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html",
          "url": "https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202305-02",
          "url": "https://security.gentoo.org/glsa/202305-02"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20210622-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20210622-0003/"
        },
        {
          "category": "external",
          "summary": "https://sick.codes/sick-2021-014",
          "url": "https://sick.codes/sick-2021-014"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com//security-alerts/cpujul2021.html",
          "url": "https://www.oracle.com//security-alerts/cpujul2021.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpuapr2022.html",
          "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujan2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujul2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpuoct2021.html",
          "url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        }
      ],
      "release_date": "2021-05-06T13:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2021-3177",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
          "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue42938",
          "url": "https://bugs.python.org/issue42938"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/24239",
          "url": "https://github.com/python/cpython/pull/24239"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html",
          "url": "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=26185005",
          "url": "https://news.ycombinator.com/item?id=26185005"
        },
        {
          "category": "external",
          "summary": "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html",
          "url": "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202101-18",
          "url": "https://security.gentoo.org/glsa/202101-18"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20210226-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20210226-0003/"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com//security-alerts/cpujul2021.html",
          "url": "https://www.oracle.com//security-alerts/cpujul2021.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujan2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujul2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpuoct2021.html",
          "url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
        }
      ],
      "release_date": "2021-01-19T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T10:10:33.907968Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032",
          "product_ids": [
            "CentOS-10:alt-python38-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-devel-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-idle-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-libs-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-test-0:3.8.20-25.el10.x86_64",
            "CentOS-10:alt-python38-tkinter-0:3.8.20-25.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788171032"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    }
  ]
}