Fedora Security Advisories

xorg-x11-server-Xwayland-24.1.14-1.fc44

3 days 4 hours ago
FEDORA-2026-2448dda850 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc44
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

xorg-x11-server-Xwayland-24.1.14-1.fc45

3 days 4 hours ago
FEDORA-2026-2460ebb288 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc45
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

curl-8.15.0-11.fc43

3 days 5 hours ago
FEDORA-2026-3ea898ea77 Packages in this update:
  • curl-8.15.0-11.fc43
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

wordpress-6.9.10-1.el9

3 days 8 hours ago
FEDORA-EPEL-2026-15d6637cee Packages in this update:
  • wordpress-6.9.10-1.el9
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.fc44

3 days 8 hours ago
FEDORA-2026-5ada1f2961 Packages in this update:
  • wordpress-6.9.10-1.fc44
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.fc43

3 days 8 hours ago
FEDORA-2026-e0ebe50146 Packages in this update:
  • wordpress-6.9.10-1.fc43
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.el10_2

3 days 8 hours ago
FEDORA-EPEL-2026-b799c5dced Packages in this update:
  • wordpress-6.9.10-1.el10_2
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.fc45

3 days 8 hours ago
FEDORA-2026-3c05ab9fa4 Packages in this update:
  • wordpress-7.1.3-1.fc45
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.el10_4

3 days 8 hours ago
FEDORA-EPEL-2026-0d5bab9c2d Packages in this update:
  • wordpress-7.1.3-1.el10_4
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.el10_3

3 days 8 hours ago
FEDORA-EPEL-2026-98aa985c34 Packages in this update:
  • wordpress-7.1.3-1.el10_3
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team
Checked
38 minutes 25 seconds ago