Aggregator
USN-8564-1: PHP vulnerabilities
USN-8560-1: libXfont vulnerabilities
USN-8559-1: rlottie vulnerabilities
USN-8563-1: nginx vulnerabilities
nodejs22-22.23.1-2.fc45
- nodejs22-22.23.1-2.fc45
Automatic update for nodejs22-22.23.1-2.fc45.
Changelog * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-2 - CVE-2026-42338 ip-address HTML escaping fix (rhbz#2487625) * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-1 - Update to version 22.23.1 (rhbz#2477273). * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:22.22.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuildbtrbk-0.32.7-1.fc43
- btrbk-0.32.7-1.fc43
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
btrbk-0.32.7-1.fc44
- btrbk-0.32.7-1.fc44
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
nginx-1.30.4-1.fc43 nginx-mod-brotli-1.0.0~rc-13.fc43 nginx-mod-fancyindex-0.6.0-8.fc43 nginx-mod-headers-more-0.40-3.fc43 nginx-mod-modsecurity-1.0.4-16.fc43 nginx-mod-naxsi-1.6-21.fc43 nginx-mod-vts-0.2.4-13.fc43
- nginx-1.30.4-1.fc43
- nginx-mod-brotli-1.0.0~rc-13.fc43
- nginx-mod-fancyindex-0.6.0-8.fc43
- nginx-mod-headers-more-0.40-3.fc43
- nginx-mod-modsecurity-1.0.4-16.fc43
- nginx-mod-naxsi-1.6-21.fc43
- nginx-mod-vts-0.2.4-13.fc43
nginx-mod-vts:
- Rebuild for 1.30.4
nginx-mod-brotli:
- Rebuild for 1.30.4
nginx-mod-fancyindex:
- Rebuild for 1.30.4
nginx-mod-headers-more:
- Rebuild for 1.30.4
nginx-mod-modsecurity:
- Rebuild for 1.30.4
nginx-mod-naxsi:
- Rebuild for 1.30.4
nginx:
- update to 1.30.4
- fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
nginx-1.30.4-1.fc44 nginx-mod-brotli-1.0.0~rc-13.fc44 nginx-mod-fancyindex-0.6.0-8.fc44 nginx-mod-headers-more-0.40-3.fc44 nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44 nginx-mod-modsecurity-1.0.4-16.fc44 nginx-mod-naxsi-1.6-21.fc44 nginx-mod-vts…
- nginx-1.30.4-1.fc44
- nginx-mod-brotli-1.0.0~rc-13.fc44
- nginx-mod-fancyindex-0.6.0-8.fc44
- nginx-mod-headers-more-0.40-3.fc44
- nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
- nginx-mod-modsecurity-1.0.4-16.fc44
- nginx-mod-naxsi-1.6-21.fc44
- nginx-mod-vts-0.2.4-13.fc44
nginx-mod-fancyindex:
- Rebuild for 1.30.4
nginx-mod-modsecurity:
- Rebuild for 1.30.4
nginx-mod-naxsi:
- Rebuild for 1.30.4
nginx-mod-headers-more:
- Rebuild for 1.30.4
nginx-mod-brotli:
- Rebuild for 1.30.4
nginx-mod-js-challenge:
- Rebuild for 1.30.4
nginx-mod-vts:
- Rebuild for 1.30.4
nginx:
- update to 1.30.4
- fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
7.2-rc4: mainline
opkssh-0.16.0-1.el10_3
- opkssh-0.16.0-1.el10_3
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
opkssh-0.16.0-1.el10_2
- opkssh-0.16.0-1.el10_2
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
opkssh-0.16.0-1.fc43
- opkssh-0.16.0-1.fc43
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
opkssh-0.16.0-1.fc44
- opkssh-0.16.0-1.fc44
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
python-pillow-11.3.0-10.fc43
- python-pillow-11.3.0-10.fc43
Backport fixes for CVE-2026-59197 and CVE-2026-54058.
Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798
perl-Mojolicious-9.48-1.fc43
- perl-Mojolicious-9.48-1.fc43
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.
perl-Mojolicious-9.48-1.fc44
- perl-Mojolicious-9.48-1.fc44
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.