Fedora Security Advisories

znc-1.10.3-1.fc44

3 hours 56 minutes ago
FEDORA-2026-855d5949d1 Packages in this update:
  • znc-1.10.3-1.fc44
Update description:

Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023

znc-1.10.3-1.fc45

4 hours ago
FEDORA-2026-3135766c09 Packages in this update:
  • znc-1.10.3-1.fc45
Update description:

Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023

perl-HTML-FormHandler-0.410002-1.fc44

9 hours 18 minutes ago
FEDORA-2026-21850d7df0 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc44
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc43

9 hours 18 minutes ago
FEDORA-2026-167a356523 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc43
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc45

9 hours 18 minutes ago
FEDORA-2026-406a152d49 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc45
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

patool-4.1.0-1.fc46

14 hours 13 minutes ago
FEDORA-2026-d38857d084 Packages in this update:
  • patool-4.1.0-1.fc46
Update description:

Automatic update for patool-4.1.0-1.fc46.

Changelog * Sun Sep 13 2026 Federico Pellegrin <fede@evolware.org> - 4.1.0-1 - Bump to 4.1.0 (rhbz#2421500 and rhbz#2508373)

opkssh-0.16.0-3.el10_3

1 day 10 hours ago
FEDORA-EPEL-2026-9f73888869 Packages in this update:
  • opkssh-0.16.0-3.el10_3
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.el10_2

1 day 10 hours ago
FEDORA-EPEL-2026-878ec4ee25 Packages in this update:
  • opkssh-0.16.0-3.el10_2
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.fc45

1 day 10 hours ago
FEDORA-2026-559bbb39f5 Packages in this update:
  • opkssh-0.16.0-3.fc45
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.fc44

1 day 10 hours ago
FEDORA-2026-f7b73f165d Packages in this update:
  • opkssh-0.16.0-3.fc44
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.fc43

1 day 10 hours ago
FEDORA-2026-38b019a0f0 Packages in this update:
  • opkssh-0.16.0-3.fc43
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

PackageKit-1.4.0-1.fc45

1 day 20 hours ago
FEDORA-2026-95d69295a4 Packages in this update:
  • PackageKit-1.4.0-1.fc45
Update description:

Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9

PackageKit-1.4.0-1.fc44

1 day 20 hours ago
FEDORA-2026-6cf9691266 Packages in this update:
  • PackageKit-1.4.0-1.fc44
Update description:

Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9

Checked
12 minutes 40 seconds ago