* Non-maintainer upload by the LTS Team.
* Apply upstream patches for the following CVEs:
- CVE-2025-13462: Incorrect parsing of TarInfo header when GNU long name
and type AREGTYPE are combined
- CVE-2026-2297: SourcelessFileLoader does not use io.open_code()
- CVE-2026-3644: Reject control characters in more places in
http.cookies.Morsel (follow-up of patch for CVE-2026-0672)
- CVE-2026-4224: pyexpat.c: Unbounded C recursion in conv_content_model
causes crash
- CVE-2026-4519: Reject leading dashes in webbrowser.open()