mirror of https://github.com/openwrt/packages.git
This is a security release. Notable Changes * (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High * (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High * (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High * (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium * (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium * (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium * (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium * (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low * (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low * (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low * deps: update llhttp to 9.4.3 (Paolo Insogna) * deps: update undici to 6.28.0 (Node.js GitHub Bot) Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com> |
||
|---|---|---|
| .. | ||
| chicken-scheme | ||
| erlang | ||
| golang | ||
| lua | ||
| node | ||
| node-javascript-obfuscator | ||
| node-yarn | ||
| perl | ||
| php8 | ||
| php8-pecl-dio | ||
| php8-pecl-http | ||
| php8-pecl-imagick | ||
| php8-pecl-krb5 | ||
| php8-pecl-raphf | ||
| php8-pecl-redis | ||
| php8-pecl-xdebug | ||
| python | ||
| quickjs | ||
| ruby | ||
| rust | ||
| tcl | ||
| vala | ||