znc-1.10.3-1.fc44
- znc-1.10.3-1.fc44
Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023
Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023
Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
release 2.0.0
release v2.0.0
Bump to 4.1.0 (rhbz#2421500 and rhbz#2508373)
Bump to 4.1.0 (rhbz#2421500 and rhbz#2508373)
Automatic update for patool-4.1.0-1.fc46.
Changelog * Sun Sep 13 2026 Federico Pellegrin <fede@evolware.org> - 4.1.0-1 - Bump to 4.1.0 (rhbz#2421500 and rhbz#2508373)Disable outdated functionality which requires outdated SDL1.
Fix for CVE-2026-57160
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9
Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9
Update to version 2.1.3.
Update to version 2.1.3.