Fedora Security Advisories

mongo-c-driver-1.30.11-1.el9

6 hours ago
FEDORA-EPEL-2026-f3189ad8bc Packages in this update:
  • mongo-c-driver-1.30.11-1.el9
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.fc43

6 hours ago
FEDORA-2026-b4c749cdd2 Packages in this update:
  • mongo-c-driver-1.30.11-1.fc43
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.el10_2

6 hours ago
FEDORA-EPEL-2026-a7a6a60c98 Packages in this update:
  • mongo-c-driver-1.30.11-1.el10_2
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.el8

6 hours ago
FEDORA-EPEL-2026-633d87af00 Packages in this update:
  • mongo-c-driver-1.30.11-1.el8
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.fc44

6 hours ago
FEDORA-2026-4286ff2dfd Packages in this update:
  • mongo-c-driver-1.30.11-1.fc44
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-2.5.4-1.fc45

6 hours 23 minutes ago
FEDORA-2026-0fcc2d09c6 Packages in this update:
  • mongo-c-driver-2.5.4-1.fc45
Update description: libmongoc 2.5.4

Fixes

  • Fix allocation in Windows Secure Channel.
libmongoc 2.5.3

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-2.5.4-1.el10_3

6 hours 23 minutes ago
FEDORA-EPEL-2026-8775c68ed7 Packages in this update:
  • mongo-c-driver-2.5.4-1.el10_3
Update description: libmongoc 2.5.4

Fixes

  • Fix allocation in Windows Secure Channel.
libmongoc 2.5.3

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-2.5.4-1.el10_4

6 hours 23 minutes ago
FEDORA-EPEL-2026-aa805ed951 Packages in this update:
  • mongo-c-driver-2.5.4-1.el10_4
Update description: libmongoc 2.5.4

Fixes

  • Fix allocation in Windows Secure Channel.
libmongoc 2.5.3

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

wordpress-6.9.8-1.el9

6 hours 39 minutes ago
FEDORA-EPEL-2026-30ba647e0d Packages in this update:
  • wordpress-6.9.8-1.el9
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.8-1.fc43

6 hours 39 minutes ago
FEDORA-2026-03794a8ad4 Packages in this update:
  • wordpress-6.9.8-1.fc43
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.8-1.el10_2

6 hours 39 minutes ago
FEDORA-EPEL-2026-92398592b0 Packages in this update:
  • wordpress-6.9.8-1.el10_2
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.8-1.fc44

6 hours 39 minutes ago
FEDORA-2026-1811aa4e7c Packages in this update:
  • wordpress-6.9.8-1.fc44
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.1-1.el10_3

6 hours 50 minutes ago
FEDORA-EPEL-2026-d3f5e5502d Packages in this update:
  • wordpress-7.1.1-1.el10_3
Update description: WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.1-1.fc45

6 hours 50 minutes ago
FEDORA-2026-4b2be5b3a2 Packages in this update:
  • wordpress-7.1.1-1.fc45
Update description: WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.1-1.el10_4

6 hours 50 minutes ago
FEDORA-EPEL-2026-86738cd79a Packages in this update:
  • wordpress-7.1.1-1.el10_4
Update description: WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.
Checked
11 minutes 14 seconds ago