Fedora Security Advisories

perl-libwww-perl-6.83-1.fc43

2 hours 25 minutes ago
FEDORA-2026-3b48ba7dc7 Packages in this update:
  • perl-libwww-perl-6.83-1.fc43
Update description:

Changes:

6.83 2026-05-12 11:41:48Z

- LWP::UserAgent now strips Authorization and Proxy-Authorization headers on cross-origin redirects (a different scheme, host, or port) to prevent credential leakage to the redirect target. Same-origin redirects retain credentials. Opt out with allow_credentialed_redirects => 1. CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig Palmquist. - LWP::UserAgent now refuses https to http redirects by default to prevent leaking remaining request headers and bodies over plaintext. Opt in with allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC by Stig Palmquist.

perl-libwww-perl-6.83-1.fc44

2 hours 31 minutes ago
FEDORA-2026-8d1333fb52 Packages in this update:
  • perl-libwww-perl-6.83-1.fc44
Update description:

Changes:

6.83 2026-05-12 11:41:48Z

- LWP::UserAgent now strips Authorization and Proxy-Authorization headers on cross-origin redirects (a different scheme, host, or port) to prevent credential leakage to the redirect target. Same-origin redirects retain credentials. Opt out with allow_credentialed_redirects => 1. CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig Palmquist. - LWP::UserAgent now refuses https to http redirects by default to prevent leaking remaining request headers and bodies over plaintext. Opt in with allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC by Stig Palmquist.

openbao-2.5.4-1.el8

3 hours 24 minutes ago
FEDORA-EPEL-2026-7c82182eba Packages in this update:
  • openbao-2.5.4-1.el8
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

openbao-2.5.4-1.el9

3 hours 24 minutes ago
FEDORA-EPEL-2026-89a3c4993d Packages in this update:
  • openbao-2.5.4-1.el9
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

openbao-2.5.4-1.fc44

3 hours 24 minutes ago
FEDORA-2026-bf7889aec6 Packages in this update:
  • openbao-2.5.4-1.fc44
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

openbao-2.5.4-1.fc42

3 hours 24 minutes ago
FEDORA-2026-b7d009831a Packages in this update:
  • openbao-2.5.4-1.fc42
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

openbao-2.5.4-1.el10_3

3 hours 24 minutes ago
FEDORA-EPEL-2026-cec027b6af Packages in this update:
  • openbao-2.5.4-1.el10_3
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

openbao-2.5.4-1.fc43

3 hours 24 minutes ago
FEDORA-2026-d4e8f0a731 Packages in this update:
  • openbao-2.5.4-1.fc43
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

openbao-2.5.4-1.el10_2

3 hours 24 minutes ago
FEDORA-EPEL-2026-cc6a962bcc Packages in this update:
  • openbao-2.5.4-1.el10_2
Update description:

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808

perl-HTTP-Tiny-0.094-1.fc43

6 hours 36 minutes ago
FEDORA-2026-3bfb774625 Packages in this update:
  • perl-HTTP-Tiny-0.094-1.fc43
Update description:

0.094 - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010)

cockpit-362-1.fc44

9 hours 2 minutes ago
FEDORA-2026-ac9d9c87c8 Packages in this update:
  • cockpit-362-1.fc44
Update description:

Automatic update for cockpit-362-1.fc44.

Changelog for cockpit * Wed May 20 2026 Packit <hello@packit.dev> - 362-1 - Bug fixes and translation updates - Fix arbitrary code execution via specially crafted logs page link (CVE-2026-4802)

cockpit-362-1.fc43

9 hours 4 minutes ago
FEDORA-2026-58cee40a55 Packages in this update:
  • cockpit-362-1.fc43
Update description:

Automatic update for cockpit-362-1.fc43.

Changelog for cockpit * Wed May 20 2026 Packit <hello@packit.dev> - 362-1 - Bug fixes and translation updates - Fix arbitrary code execution via specially crafted logs page link (CVE-2026-4802)
Checked
5 minutes 46 seconds ago