Aggregator
cpp-httplib-0.38.0-1.fc44
- cpp-httplib-0.38.0-1.fc44
- Filename sanitization for path traversal prevention — Added sanitize_filename() to prevent path traversal attacks via malicious filenames in multipart uploads (83e98a2)
-
Symlink protection in static file server — Static file serving now detects and rejects symlinks that point outside the mount directory, preventing symlink-based directory traversal (f787f31)
-
Brotli compression support — Added Brotli (br) as a supported content encoding alongside gzip and deflate (ec1ffbc)
- Accept-Encoding quality parameter parsing — The server now parses q= quality values in the Accept-Encoding header and selects the best encoding accordingly (bb7c7ab)
- SSL proxy connection support — SSLClient can now establish connections through HTTPS proxies, with a new setup_proxy_connection method for cleaner proxy handling (f6ed5fc, b1bb2b7)
-
WebSocket ping interval runtime configuration — WebSocket ping interval can now be configured at runtime instead of only at compile time (257b266)
-
Benchmark test suite — Added benchmark tests and configurations for performance evaluation (ba0d0b8)
- Unicode path component decoding tests — Added test coverage for Unicode characters in decode_path_component (43a54a3)
-
Documentation updates — Enhanced TLS backend documentation with platform-specific certificate handling details; clarified progress callback usage and user data handling in examples (511e3ef, 2e61fd3)
-
Fix port conflict in test — Fixed port number in OpenStreamMalformedContentLength test to avoid conflicts (4978f26)
-
Removed large data tests for GzipDecompressor and SSLClientServerTest that caused memory issues (5ecba74, 69d468f)
- Enabled BindDualStack test (69d468f)
Source: https://github.com/yhirose/cpp-httplib/releases/tag/v0.38.0
- Fixes silent TLS certificate verification bypass on HTTPS Redirect via proxy (CVE-2026-32627, rhbz#2448105)
Source: https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.2
perl-XML-Parser-2.51-1.fc42
- perl-XML-Parser-2.51-1.fc42
2.51 bump - Fix CVE-2006-10002, CVE-2006-10003
perl-XML-Parser-2.51-1.fc43
- perl-XML-Parser-2.51-1.fc43
2.51 bump - Fix CVE-2006-10002, CVE-2006-10003
perl-XML-Parser-2.51-1.fc44
- perl-XML-Parser-2.51-1.fc44
2.51 bump - Fix CVE-2006-10002, CVE-2006-10003
perl-XML-Parser-2.51-1.fc45
- perl-XML-Parser-2.51-1.fc45
Automatic update for perl-XML-Parser-2.51-1.fc45.
Changelog * Mon Mar 23 2026 Jitka Plesnikova <jplesnik@redhat.com> - 2.51-1 - 2.51 bump (rhbz#2448965) - Fix CVE-2006-10002 (rhbz#2449269), CVE-2006-10003 (rhbz#2449278)rust-cargo-c-0.10.19-2.fc42
- rust-cargo-c-0.10.19-2.fc42
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-sccache-0.13.0-4.fc44
- rust-sccache-0.13.0-4.fc44
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-ingredients-0.2.2-3.fc44
- rust-ingredients-0.2.2-3.fc44
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-cargo-vendor-filterer-0.5.18-4.el10_3
- rust-cargo-vendor-filterer-0.5.18-4.el10_3
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-cargo-vendor-filterer-0.5.18-4.fc42
- rust-cargo-vendor-filterer-0.5.18-4.fc42
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-cargo-vendor-filterer-0.5.18-4.fc43
- rust-cargo-vendor-filterer-0.5.18-4.fc43
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-cargo-rpmstatus-0.2.4-3.fc42
- rust-cargo-rpmstatus-0.2.4-3.fc42
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
rust-cargo-c-0.10.19-2.fc43
- rust-cargo-c-0.10.19-2.fc43
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
DSA-6176-1 strongswan - security update
libopenmpt-0.8.5-1.fc43
- libopenmpt-0.8.5-1.fc43
Potential security fix plus bug-fixes in 0.8.5: https://lib.openmpt.org/libopenmpt/2026/03/22/security-updates-0.8.5-0.7.18-0.6.27-0.5.41-0.4.53/
libopenmpt-0.8.5-1.fc44
- libopenmpt-0.8.5-1.fc44
Potential security fix plus bug-fixes in 0.8.5: https://lib.openmpt.org/libopenmpt/2026/03/22/security-updates-0.8.5-0.7.18-0.6.27-0.5.41-0.4.53/
libopenmpt-0.8.5-1.fc42
- libopenmpt-0.8.5-1.fc42
Potential security fix plus bug-fixes in 0.8.5: https://lib.openmpt.org/libopenmpt/2026/03/22/security-updates-0.8.5-0.7.18-0.6.27-0.5.41-0.4.53/
7.0-rc5: mainline
ntpd-rs-1.7.1-1.el10_1
- ntpd-rs-1.7.1-1.el10_1
Update to version 1.7.1.
Includes the fix for CVE-2026-26076: https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-c7j7-rmvr-fjmv
Release notes: