Aggregator
DSA-6288-1 thunderbird - security update
DSA-6286-1 evince - security update
docker-compose-5.1.4-1.fc43
- docker-compose-5.1.4-1.fc43
- Update to release v5.1.4
- Resolves: rhbz#2480186
- Upstream fixes
- Update to release v5.1.3
- Resolves rhbz#2458697
- Resolves CVE-2026-33747: rhbz#2452188, rhbz#2452199
- Resolves CVE-2026-33748: rhbz#2453089
- Upstream fixes
docker-compose-5.1.4-1.fc44
- docker-compose-5.1.4-1.fc44
- Update to release v5.1.4
- Resolves: rhbz#2480186
- Upstream fixes
- Update to release v5.1.3
- Resolves rhbz#2458697
- Resolves CVE-2026-33747: rhbz#2452188, rhbz#2452199
- Resolves CVE-2026-33748: rhbz#2453089
- Upstream fixes
USN-8289-1: Linux kernel (NVIDIA) vulnerabilities
mapserver-8.6.3-1.fc43
- mapserver-8.6.3-1.fc43
Update to mapserver-8.6.3.
podofo-1.0.4-1.fc44
- podofo-1.0.4-1.fc44
Update to podof-1.0.4.
podofo-1.0.4-1.fc43
- podofo-1.0.4-1.fc43
Update to podof-1.0.4.
mingw-qt6-qtsvg-6.10.3-2.fc43
- mingw-qt6-qtsvg-6.10.3-2.fc43
Backport fix for CVE-2026-6210.
ansible-13.7.0-1.fc45 ansible-core-2.20.6-1.fc45
- ansible-13.7.0-1.fc45
- ansible-core-2.20.6-1.fc45
Latest Ansible 13
- Close bogus CVEs
perl-libwww-perl-6.83-1.fc43
- perl-libwww-perl-6.83-1.fc43
Changes:
6.83 2026-05-12 11:41:48Z
- LWP::UserAgent now strips Authorization and Proxy-Authorization headers on cross-origin redirects (a different scheme, host, or port) to prevent credential leakage to the redirect target. Same-origin redirects retain credentials. Opt out with allow_credentialed_redirects => 1. CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig Palmquist. - LWP::UserAgent now refuses https to http redirects by default to prevent leaking remaining request headers and bodies over plaintext. Opt in with allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC by Stig Palmquist.perl-libwww-perl-6.83-1.fc44
- perl-libwww-perl-6.83-1.fc44
Changes:
6.83 2026-05-12 11:41:48Z
- LWP::UserAgent now strips Authorization and Proxy-Authorization headers on cross-origin redirects (a different scheme, host, or port) to prevent credential leakage to the redirect target. Same-origin redirects retain credentials. Opt out with allow_credentialed_redirects => 1. CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig Palmquist. - LWP::UserAgent now refuses https to http redirects by default to prevent leaking remaining request headers and bodies over plaintext. Opt in with allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC by Stig Palmquist.openbao-2.5.4-1.el8
- openbao-2.5.4-1.el8
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808
openbao-2.5.4-1.el9
- openbao-2.5.4-1.el9
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808
openbao-2.5.4-1.fc44
- openbao-2.5.4-1.fc44
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808
openbao-2.5.4-1.fc42
- openbao-2.5.4-1.fc42
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808
openbao-2.5.4-1.el10_3
- openbao-2.5.4-1.el10_3
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808
openbao-2.5.4-1.fc43
- openbao-2.5.4-1.fc43
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808
openbao-2.5.4-1.el10_2
- openbao-2.5.4-1.el10_2
Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808