Update to upstream 10.1.4 Resolves: - CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy bypass - CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not stripped - CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling - CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the server - CVE-2026-58154 - Memory-safety errors in MIME and header parsing - CVE-2026-58155 - Header-name length truncation enables header aliasing and request smuggling - CVE-2026-58157 - Improper server-session reuse can expose data across client connections - CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the server - CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts framework - CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion - CVE-2026-24033 - Chunked extension quoted-string parsing allows request smuggling - CVE-2026-33930 - Buffer overflow via Host field that has a long string value - CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing host-SNI policy bypass - CVE-2026-57834 - Malformed chunked message body allows request smuggling - CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt memory - CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely - CVE-2026-58156 - URL and port parsing errors allow access-control bypass - CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack overflow - CVE-2026-58159 - Listener and ACL handling allow access-control bypass - CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses - CVE-2026-58162 - Certifier plugin trusts client SNI when generating certificates - CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state or crash the server - CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-after-free - CVE-2026-58175 - HostDB SRV handling leaks memory - CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side request forgery - CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input - CVE-2026-58180 - txn_box plugin overflows the stack from attacker input - CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or crash - CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors - CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input - CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory - CVE-2026-58185 - Use-after-free in the intercept plugin - CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded responses - CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service - CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental plugins - CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF amplification - CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed header encode - CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without certificate re-verification
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2026-5bec7441bb
Please log in to add feedback.
This update has been submitted for testing by jered.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'passed'.
jered edited this update.
This update has been pushed to testing.
jered edited this update.
This update has been submitted for stable by bodhi.
This update has been pushed to stable.