Aggregator
5.15.206: longterm
USN-8248-2: NASM regression
python-pulp-glue-0.37.0-5.fc43 python-requests-2.33.1-1.fc43
- python-pulp-glue-0.37.0-5.fc43
- python-requests-2.33.1-1.fc43
Bugfixes - Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. - Fixed Content-Type header parsing for malformed values. - Improved error consistency for malformed header values.
2.33.0 (2026-03-25)Announcements - 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣
Security - CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.
Improvements - Migrated to a PEP 517 build system using setuptools.
Bugfixes - Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+.
Deprecations - Dropped support for Python 3.9 following its end of support.
Documentation - Various typo fixes and doc improvements.
python-pulp-glue-0.37.0-5.fc44 python-requests-2.33.1-1.fc44
- python-pulp-glue-0.37.0-5.fc44
- python-requests-2.33.1-1.fc44
Bugfixes - Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. - Fixed Content-Type header parsing for malformed values. - Improved error consistency for malformed header values.
2.33.0 (2026-03-25)Announcements - 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣
Security - CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.
Improvements - Migrated to a PEP 517 build system using setuptools.
Bugfixes - Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+.
Deprecations - Dropped support for Python 3.9 following its end of support.
Documentation - Various typo fixes and doc improvements.
next-20260508: linux-next
6.1.171: longterm
5.15.205: longterm
5.10.255: longterm
USN-8262-1: Lua vulnerability
7.0.5: stable
6.18.28: longterm
6.12.87: longterm
6.6.138: longterm
DSA-6253-1 linux - security update
DSA-6254-1 firefox-esr - security update
DSA-6255-1 php8.2 - security update
DSA-6256-1 php8.4 - security update
DSA-6257-1 postorius - security update
python-jupytext-1.19.1-4.fc42
- python-jupytext-1.19.1-4.fc42
This update contains upgrades to various npm packages used during the build to address CVEs, namely:
- CVE-2025-69873 (ajv)
- CVE-2026-0540 (DOMPurify)
- CVE-2026-3449 (@tootallnate/once)
- CVE-2026-4800 (lodash)
- CVE-2026-6321 (fast-uri)
- CVE-2026-41240 (DOMPurify)
This is probably unimportant since these packages are used at build-time only. They are not shipped with python3-jupytext and therefore do not affect runtime.