opkssh-0.16.0-2.el10_3
- opkssh-0.16.0-2.el10_3
Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).
opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.