Aggregator

nghttp2-1.66.0-3.fc43

1 hour 11 minutes ago
FEDORA-2026-91dd0c29d6 Packages in this update:
  • nghttp2-1.66.0-3.fc43
Update description:
  • fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

nghttp2-1.68.0-5.fc44

1 hour 11 minutes ago
FEDORA-2026-084c991d17 Packages in this update:
  • nghttp2-1.68.0-5.fc44
Update description:
  • fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

stunnel-5.80-1.fc43

3 hours 3 minutes ago
FEDORA-2026-de8630b736 Packages in this update:
  • stunnel-5.80-1.fc43
Update description: * Security bugfixes - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang). - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang). - Restricted Windows GUI/service control pipes to local clients. * Bugfixes - Fixed concurrent DTLS handshakes from clients sharing an IP address. - Fixed version reporting in builds from source. - Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation. - Fixed a TCP stream truncation (thanks to Solomon Jacobs). - Fixed a transfer() loop (thanks to Solomon Jacobs). - Fixed log reopening logs without a configured log file. - Fixed some logged values (thanks to Jose Alf.). - Fixed some error handling and cleanup issues (thanks to Jose Alf.). - Fixed OpenSSL applink detection and MSYS2 MinGW builds. * Features - Added the "CRLcheckChain" service-level option for opt-in full-chain CRL verification. - Added the new 'transport' service-level option to choose between TLS over TCP and DTLS over UDP.

stunnel-5.80-1.fc44

3 hours 4 minutes ago
FEDORA-2026-67c2201ad8 Packages in this update:
  • stunnel-5.80-1.fc44
Update description: * Security bugfixes - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang). - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang). - Restricted Windows GUI/service control pipes to local clients. * Bugfixes - Fixed concurrent DTLS handshakes from clients sharing an IP address. - Fixed version reporting in builds from source. - Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation. - Fixed a TCP stream truncation (thanks to Solomon Jacobs). - Fixed a transfer() loop (thanks to Solomon Jacobs). - Fixed log reopening logs without a configured log file. - Fixed some logged values (thanks to Jose Alf.). - Fixed some error handling and cleanup issues (thanks to Jose Alf.). - Fixed OpenSSL applink detection and MSYS2 MinGW builds. * Features - Added the "CRLcheckChain" service-level option for opt-in full-chain CRL verification. - Added the new 'transport' service-level option to choose between TLS over TCP and DTLS over UDP.

wordpress-6.9.6-1.fc43

8 hours 2 minutes ago
FEDORA-2026-35a50f466b Packages in this update:
  • wordpress-6.9.6-1.fc43
Update description: Security updates included in this release
  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.6-1.el10_2

8 hours 2 minutes ago
FEDORA-EPEL-2026-180c91b119 Packages in this update:
  • wordpress-6.9.6-1.el10_2
Update description: Security updates included in this release
  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.6-1.el9

8 hours 2 minutes ago
FEDORA-EPEL-2026-ced33edbed Packages in this update:
  • wordpress-6.9.6-1.el9
Update description: Security updates included in this release
  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.6-1.fc44

8 hours 2 minutes ago
FEDORA-2026-572debb8a7 Packages in this update:
  • wordpress-6.9.6-1.fc44
Update description: Security updates included in this release
  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-7.0.3-1.el10_3

8 hours 2 minutes ago
FEDORA-EPEL-2026-43fd90996e Packages in this update:
  • wordpress-7.0.3-1.el10_3
Update description: Security updates included in this release
  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters