The following Fedora EPEL 8 Security updates need testing:
Age URL
114 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5b2095e2c2 xpdf-4.06-1.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-9bebf8a3c3 zabbix6.0-6.0.44-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
python-scitokens-1.9.7-1.el8
snapd-2.74.1-0.el8
Details about builds:
================================================================================
python-scitokens-1.9.7-1.el8 (FEDORA-EPEL-2026-9aaf8075c2)
SciToken reference implementation library
--------------------------------------------------------------------------------
Update Information:
Remove legacy parent SciToken chaining behavior from token initialization and
claim handling
Harden Enforcer scope path traversal validation (including encoded traversal
checks)
Clean up documentation references to parent/chained SciTokens
Fix SQL injection risk in KeyCache by using parameterized SQLite queries
Prevent sibling-path authorization bypass in Enforcer scope checks
--------------------------------------------------------------------------------
ChangeLog:
* Fri Mar 13 2026 Derek Weitzel <dweitzel(a)unl.edu> - 1.9.7-1
- Remove legacy parent SciToken chaining behavior from token initialization and claim handling
- Harden Enforcer scope path traversal validation (including encoded traversal checks)
- Clean up documentation references to parent/chained SciTokens
* Fri Mar 13 2026 Derek Weitzel <dweitzel(a)unl.edu> - 1.9.6-1
- Fix SQL injection risk in KeyCache by using parameterized SQLite queries
- Prevent sibling-path authorization bypass in Enforcer scope checks
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.9.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
snapd-2.74.1-0.el8 (FEDORA-EPEL-2026-2e2007a26d)
A transactional software package manager
--------------------------------------------------------------------------------
Update Information:
New upstream release 2.74.1
--------------------------------------------------------------------------------
ChangeLog:
* Fri Mar 13 2026 Ernest Lotter <ernest.lotter(a)canonical.com>
- New upstream release 2.74.1
- FDE: measure DeployedMode and AuditMode variables if they appear
as disabled in the event log to avoid a potential reseal-failure
boot loop
- LP: #2139611 FDE: fix db updates by allowing multiple payloads
- LP: #2139300 snap-confine: add CAP_SYS_RESOURCE to allow raising
memory lock limit when required
- LP: #2139099 snap-confine: bump the max element count of the BPF
map used to store IDs of allowed/matched devices to 1000
- Interfaces: Added pidfd_open and memfd_secret to seccomp template
- Interfaces: camera | add locking permission for /dev/video
* Tue Feb 17 2026 Neal Gompa <ngompa(a)fedoraproject.org> - 2.72-4
- Default to vendored Go dependencies in Fedora
* Tue Feb 3 2026 Maxwell G <maxwell(a)gtmx.me> - 2.72-3
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.72-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
The following Fedora EPEL 10.1 Security updates need testing:
Age URL
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-439d2b09db wordpress-6.9.4-1.el10_1
The following builds have been pushed to Fedora EPEL 10.1 updates-testing
Pencil2D-0.7.2-1.el10_1
duf-0.9.1-3.el10_1
python-ujson-5.12.0-1.el10_1
Details about builds:
================================================================================
Pencil2D-0.7.2-1.el10_1 (FEDORA-EPEL-2026-d1cd59ed84)
Create traditional hand-drawn animation (cartoon)
--------------------------------------------------------------------------------
Update Information:
Update to 0.7.2: fixes AppStream metadata that was not updated for 0.7.1.
Update to 0.7.1, and hide “Check for Updates” in the Help menu.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Mar 13 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.2-1
- Update to 0.7.2 (close RHBZ#2447247)
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.1-2
- Hide “Check for Updates” in the Help menu
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.1-1
- Update to 0.7.1 (close RHBZ#2445414)
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.0-15
- Port (downstream-only for now) to Catch2 3.x
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.0-14
- Fix Qt 6.10.1 compatibility
* Tue Mar 10 2026 Yaakov Selkowitz <yselkowi(a)redhat.com> - 0.7.0-13
- Fix flatpak build
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2447247 - Pencil2D-0.7.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2447247
--------------------------------------------------------------------------------
================================================================================
duf-0.9.1-3.el10_1 (FEDORA-EPEL-2026-6dc08c62f6)
Disk Usage/Free Utility - a better 'df' alternative
--------------------------------------------------------------------------------
Update Information:
Initial builds for EL
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 2 2026 Maxwell G <maxwell(a)gtmx.me> - 0.9.1-3
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.9.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Mon Dec 29 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.9.1-1
- Update to 0.9.1 - Closes rhbz#2393952
* Fri Oct 10 2025 Alejandro Sáez <asm(a)redhat.com> - 0.9.0-3
- rebuild
* Tue Sep 9 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.9.0-2
- Integrate Packit with Go Vendor Tools
* Mon Sep 8 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.9.0-1
- Update to 0.9.0 - Closes rhbz#2393783
* Fri Aug 15 2025 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-18
- Rebuild for golang-1.25.0
* Fri Aug 15 2025 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-17
- Revert "Rebuild for golang-1.25.0"
* Fri Aug 15 2025 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-16
- Rebuild for golang-1.25.0
* Wed Jul 23 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.8.1-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 7 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.8.1-14
- Update to latest commit and adopt Go Vendor Tools
* Thu Jan 16 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.8.1-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Wed Jul 17 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.8.1-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sun Apr 7 2024 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.8.1-11
- Cleanup spec
* Sun Feb 11 2024 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-10
- Rebuild for golang 1.22.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2447331 - [RFE:EPEL10] Please branch and build duf for EPEL10
https://bugzilla.redhat.com/show_bug.cgi?id=2447331
--------------------------------------------------------------------------------
================================================================================
python-ujson-5.12.0-1.el10_1 (FEDORA-EPEL-2026-fcc952d28d)
Ultra fast JSON encoder and decoder written in pure C
--------------------------------------------------------------------------------
Update Information:
Update to 5.12.0. This release updates the license field in the Python
metadata and fixes a buffer overflow/infinite loop from indent handling.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.12.0-1
- Update to 5.12.0 (close RHBZ#2446884)
* Thu Mar 12 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.11.0-6
- Use a pkgconfig(…) BR on double-conversion
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.11.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Thu Aug 21 2025 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.11.0-1
- Update to 5.11.0 (close RHBZ#2389730)
* Fri Jul 25 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.10.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jun 2 2025 Python Maint <python-maint(a)redhat.com> - 5.10.0-3
- Rebuilt for Python 3.14
* Sat Jan 18 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.10.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2446884 - python-ujson-5.12.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2446884
--------------------------------------------------------------------------------
The following Fedora EPEL 10.2 Security updates need testing:
Age URL
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-6d9113a8af wordpress-6.9.4-1.el10_2
The following builds have been pushed to Fedora EPEL 10.2 updates-testing
Pencil2D-0.7.2-1.el10_2
betterleaks-1.1.0-2.el10_2
chromium-146.0.7680.71-1.el10_2
duf-0.9.1-3.el10_2
picosat-965-28.el10_2
python-ujson-5.12.0-1.el10_2
Details about builds:
================================================================================
Pencil2D-0.7.2-1.el10_2 (FEDORA-EPEL-2026-e85363b64d)
Create traditional hand-drawn animation (cartoon)
--------------------------------------------------------------------------------
Update Information:
Update to 0.7.2: fixes AppStream metadata that was not updated for 0.7.1.
Update to 0.7.1, and hide “Check for Updates” in the Help menu.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Mar 13 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.2-1
- Update to 0.7.2 (close RHBZ#2447247)
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.1-2
- Hide “Check for Updates” in the Help menu
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.1-1
- Update to 0.7.1 (close RHBZ#2445414)
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.0-15
- Port (downstream-only for now) to Catch2 3.x
* Tue Mar 10 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.7.0-14
- Fix Qt 6.10.1 compatibility
* Tue Mar 10 2026 Yaakov Selkowitz <yselkowi(a)redhat.com> - 0.7.0-13
- Fix flatpak build
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2447247 - Pencil2D-0.7.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2447247
--------------------------------------------------------------------------------
================================================================================
betterleaks-1.1.0-2.el10_2 (FEDORA-EPEL-2026-24f3a9cf00)
Secrets scanner built for configurability and speed
--------------------------------------------------------------------------------
Update Information:
Update to 1.1.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri Mar 13 2026 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 1.1.0-1
- Update to 1.1.0 - Closes rhbz#2444984
--------------------------------------------------------------------------------
================================================================================
chromium-146.0.7680.71-1.el10_2 (FEDORA-EPEL-2026-004b05bae9)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 146.0.7680.71
* CVE-2026-3913: Heap buffer overflow in WebML
* CVE-2026-3914: Integer overflow in WebML
* CVE-2026-3915: Heap buffer overflow in WebML
* CVE-2026-3916: Out of bounds read in Web Speech
* CVE-2026-3917: Use after free in Agents
* CVE-2026-3918: Use after free in WebMCP
* CVE-2026-3919: Use after free in Extensions
* CVE-2026-3920: Out of bounds memory access in WebML
* CVE-2026-3921: Use after free in TextEncoding
* CVE-2026-3922: Use after free in MediaStream
* CVE-2026-3923: Use after free in WebMIDI
* CVE-2026-3924: Use after free in WindowDialog
* CVE-2026-3925: Incorrect security UI in LookalikeChecks
* CVE-2026-3926: Out of bounds read in V8
* CVE-2026-3927: Incorrect security UI in PictureInPicture
* CVE-2026-3928: Insufficient policy enforcement in Extensions
* CVE-2026-3929: Side-channel information leakage in ResourceTiming
* CVE-2026-3930: Unsafe navigation in Navigation
* CVE-2026-3931: Heap buffer overflow in Skia
* CVE-2026-3932: Insufficient policy enforcement in PDF
* CVE-2026-3934: Insufficient policy enforcement in ChromeDriver
* CVE-2026-3935: Incorrect security UI in WebAppInstalls
* CVE-2026-3936: Use after free in WebView
* CVE-2026-3937: Incorrect security UI in Downloads
* CVE-2026-3938: Insufficient policy enforcement in Clipboard
* CVE-2026-3939: Insufficient policy enforcement in PDF
* CVE-2026-3940: Insufficient policy enforcement in DevTools
* CVE-2026-3941: Insufficient policy enforcement in DevTools
* CVE-2026-3942: Incorrect security UI in PictureInPicture
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Than Ngo <than(a)redhat.com> - 146.0.7680.71-1
- Update to 146.0.7680.71
* CVE-2026-3913: Heap buffer overflow in WebML
* CVE-2026-3914: Integer overflow in WebML
* CVE-2026-3915: Heap buffer overflow in WebML
* CVE-2026-3916: Out of bounds read in Web Speech
* CVE-2026-3917: Use after free in Agents
* CVE-2026-3918: Use after free in WebMCP
* CVE-2026-3919: Use after free in Extensions
* CVE-2026-3920: Out of bounds memory access in WebML
* CVE-2026-3921: Use after free in TextEncoding
* CVE-2026-3922: Use after free in MediaStream
* CVE-2026-3923: Use after free in WebMIDI
* CVE-2026-3924: Use after free in WindowDialog
* CVE-2026-3925: Incorrect security UI in LookalikeChecks
* CVE-2026-3926: Out of bounds read in V8
* CVE-2026-3927: Incorrect security UI in PictureInPicture
* CVE-2026-3928: Insufficient policy enforcement in Extensions
* CVE-2026-3929: Side-channel information leakage in ResourceTiming
* CVE-2026-3930: Unsafe navigation in Navigation
* CVE-2026-3931: Heap buffer overflow in Skia
* CVE-2026-3932: Insufficient policy enforcement in PDF
* CVE-2026-3934: Insufficient policy enforcement in ChromeDriver
* CVE-2026-3935: Incorrect security UI in WebAppInstalls
* CVE-2026-3936: Use after free in WebView
* CVE-2026-3937: Incorrect security UI in Downloads
* CVE-2026-3938: Insufficient policy enforcement in Clipboard
* CVE-2026-3939: Insufficient policy enforcement in PDF
* CVE-2026-3940: Insufficient policy enforcement in DevTools
* CVE-2026-3941: Insufficient policy enforcement in DevTools
* CVE-2026-3942: Incorrect security UI in PictureInPicture
--------------------------------------------------------------------------------
================================================================================
duf-0.9.1-3.el10_2 (FEDORA-EPEL-2026-1694b4659b)
Disk Usage/Free Utility - a better 'df' alternative
--------------------------------------------------------------------------------
Update Information:
Initial builds for EL
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 2 2026 Maxwell G <maxwell(a)gtmx.me> - 0.9.1-3
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.9.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Mon Dec 29 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.9.1-1
- Update to 0.9.1 - Closes rhbz#2393952
* Fri Oct 10 2025 Alejandro Sáez <asm(a)redhat.com> - 0.9.0-3
- rebuild
* Tue Sep 9 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.9.0-2
- Integrate Packit with Go Vendor Tools
* Mon Sep 8 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.9.0-1
- Update to 0.9.0 - Closes rhbz#2393783
* Fri Aug 15 2025 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-18
- Rebuild for golang-1.25.0
* Fri Aug 15 2025 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-17
- Revert "Rebuild for golang-1.25.0"
* Fri Aug 15 2025 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-16
- Rebuild for golang-1.25.0
* Wed Jul 23 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.8.1-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 7 2025 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.8.1-14
- Update to latest commit and adopt Go Vendor Tools
* Thu Jan 16 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.8.1-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Wed Jul 17 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.8.1-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sun Apr 7 2024 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 0.8.1-11
- Cleanup spec
* Sun Feb 11 2024 Maxwell G <maxwell(a)gtmx.me> - 0.8.1-10
- Rebuild for golang 1.22.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2447331 - [RFE:EPEL10] Please branch and build duf for EPEL10
https://bugzilla.redhat.com/show_bug.cgi?id=2447331
--------------------------------------------------------------------------------
================================================================================
picosat-965-28.el10_2 (FEDORA-EPEL-2026-806f213586)
A SAT solver
--------------------------------------------------------------------------------
Update Information:
Build for EPEL10
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 7 2025 Jerry James <loganjerry(a)gmail.com> - 965-28
- Stop building for 32-bit x86
- Minor spec file cleanups
* Fri Jul 25 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 965-27
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Fri Apr 18 2025 Iñaki Úcar <iucar(a)fedoraproject.org> - 965-26
- R-maint-sig mass rebuild
* Fri Apr 18 2025 Iñaki Úcar <iucar(a)fedoraproject.org> - 965-25
- R-maint-sig mass rebuild
* Fri Apr 18 2025 Iñaki Úcar <iucar(a)fedoraproject.org> - 965-24
- R-maint-sig mass rebuild
* Sat Jan 18 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 965-23
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jul 19 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 965-22
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Apr 25 2024 Iñaki Úcar <iucar(a)fedoraproject.org> - 965-21
- R-maint-sig mass rebuild
* Thu Jan 25 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 965-20
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 965-19
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
python-ujson-5.12.0-1.el10_2 (FEDORA-EPEL-2026-c1187798e7)
Ultra fast JSON encoder and decoder written in pure C
--------------------------------------------------------------------------------
Update Information:
Update to 5.12.0. This release updates the license field in the Python
metadata and fixes a buffer overflow/infinite loop from indent handling.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.12.0-1
- Update to 5.12.0 (close RHBZ#2446884)
* Thu Mar 12 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.11.0-6
- Use a pkgconfig(…) BR on double-conversion
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.11.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Thu Aug 21 2025 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.11.0-1
- Update to 5.11.0 (close RHBZ#2389730)
* Fri Jul 25 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.10.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jun 2 2025 Python Maint <python-maint(a)redhat.com> - 5.10.0-3
- Rebuilt for Python 3.14
* Sat Jan 18 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.10.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2446884 - python-ujson-5.12.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2446884
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
113 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5b2095e2c2 xpdf-4.06-1.el8
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-9bebf8a3c3 zabbix6.0-6.0.44-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
goaccess-1.10.1-2.el8
kiwi-9.25.22-1.el8
python-specfile-0.40.0-1.el8
Details about builds:
================================================================================
goaccess-1.10.1-2.el8 (FEDORA-EPEL-2026-90e5a3e46c)
Real-time web log analyzer and interactive viewer
--------------------------------------------------------------------------------
Update Information:
update to 1.10.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Jonathan Wright <jonathan(a)almalinux.org> - 1.10.1-2
- RPMAUTOSPEC: unresolvable merge
--------------------------------------------------------------------------------
================================================================================
kiwi-9.25.22-1.el8 (FEDORA-EPEL-2026-21fbea0204)
Flexible operating system image builder
--------------------------------------------------------------------------------
Update Information:
Update to 9.25.22 and backport fix for SELinux labeling when making live ISOs
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Neal Gompa <ngompa(a)fedoraproject.org> - 9.25.22-1
- Update to 9.25.22
- Backport fix for SELinux in live ISOs
--------------------------------------------------------------------------------
================================================================================
python-specfile-0.40.0-1.el8 (FEDORA-EPEL-2026-ea570096fb)
A library for parsing and manipulating RPM spec files
--------------------------------------------------------------------------------
Update Information:
Automatic update for python-specfile-0.40.0-1.el8.
Changelog for python-specfile
* Wed Mar 11 2026 Packit <hello(a)packit.dev> - 0.40.0-1
- `Specfile()` has a new `sanitize` option that enables best effort sanitization
of potentially dangerous constructs such as shell expansions and unsafe Lua
macros before they are passed to RPM for parsing. (#519)
- Fixed incorrect parsing of nested macros. (#522)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 11 2026 Packit <hello(a)packit.dev> - 0.40.0-1
- `Specfile()` has a new `sanitize` option that enables best effort sanitization of potentially dangerous constructs such as shell expansions and unsafe Lua macros before they are passed to RPM for parsing. (#519)
- Fixed incorrect parsing of nested macros. (#522)
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
113 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-9a55de96db xpdf-4.06-1.el9
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-eff2326058 alertmanager-0.31.1-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
algol68g-3.10.13-1.el9
cpp-httplib-0.37.1-2.el9
goaccess-1.10.1-2.el9
keepassxc-2.7.12-1.el9
python-configargparse-1.7.5-1.el9
rust-quick-xml-0.39.2-1.el9
rust-quick-xml0.38-0.38.4-1.el9
tmt-1.69.0-1.el9
wordpress-6.9.4-1.el9
Details about builds:
================================================================================
algol68g-3.10.13-1.el9 (FEDORA-EPEL-2026-8eeb54319e)
Algol 68 Genie compiler-interpreter
--------------------------------------------------------------------------------
Update Information:
Update to 3.10.13
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Oleg Girko <ol(a)infoserver.lv> - 3.10.13-1
- Update to 3.10.13
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2444675 - algol68g-3.10.13 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2444675
--------------------------------------------------------------------------------
================================================================================
cpp-httplib-0.37.1-2.el9 (FEDORA-EPEL-2026-53aded8e0e)
A C++11 single-file header-only cross platform HTTP/HTTPS library
--------------------------------------------------------------------------------
Update Information:
Update to 0.37.1 (rbhz#2445943)
Fixes Denial of Service via malformed Content-Length header
(CVE-2026-31870)
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-39q5-hh6x-j…https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.1
Update to 0.37.0 (rhbz#2441656)
Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076,
rhbz#2445663)
Update to 0.35.0
Payload size limit bypass via gzip decompression in ContentReader (streaming)
allows oversized request bodies (CVE-2026-28435, rhbz#2444638)
Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response
header (CVE-2026-28434, rhbz#2444636)
https://github.com/yhirose/cpp-httplib/compare/v0.32.0...v0.37.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Petr Menšík <pemensik(a)redhat.com> - 0.37.1-2
- Build for 32 bits again
* Thu Mar 12 2026 Petr Menšík <pemensik(a)redhat.com> - 0.37.1-1
- Update to 0.37.1 (rhbz#2445943)
- Fixes Denial of Service via malformed Content-Length header
(CVE-2026-31870)
- https://github.com/yhirose/cpp-
httplib/security/advisories/GHSA-39q5-hh6x-jpxx
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.1
* Mon Mar 9 2026 Petr Menšík <pemensik(a)redhat.com> - 0.37.0-1
- Update to 0.37.0 (rhbz#2441656)
- Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2426698 - CVE-2026-21428 cpp-httplib: cpp-httplib: Server-Side Request Forgery via header injection [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2426698
[ 2 ] Bug #2428892 - CVE-2026-22776 cpp-httplib: cpp-httplib: Denial of Service due to excessive memory usage from compressed HTTP request bodies [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2428892
[ 3 ] Bug #2441656 - cpp-httplib-0.37.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2441656
[ 4 ] Bug #2444635 - CVE-2026-28434 cpp-httplib: default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2444635
[ 5 ] Bug #2444637 - CVE-2026-28435 cpp-httplib: payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2444637
[ 6 ] Bug #2445664 - CVE-2026-29076 cpp-httplib: cpp-httplib: Denial of Service via crafted HTTP POST request [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2445664
[ 7 ] Bug #2445943 - cpp-httplib-0.37.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2445943
[ 8 ] Bug #2446925 - CVE-2026-31870 cpp-httplib: cpp-httplib: Denial of Service via malformed Content-Length header [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2446925
--------------------------------------------------------------------------------
================================================================================
goaccess-1.10.1-2.el9 (FEDORA-EPEL-2026-803c300afe)
Real-time web log analyzer and interactive viewer
--------------------------------------------------------------------------------
Update Information:
update to 1.10.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Jonathan Wright <jonathan(a)almalinux.org> - 1.10.1-2
- RPMAUTOSPEC: unresolvable merge
--------------------------------------------------------------------------------
================================================================================
keepassxc-2.7.12-1.el9 (FEDORA-EPEL-2026-034949dcdc)
Cross-platform password manager
--------------------------------------------------------------------------------
Update Information:
2.7.12 release
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 11 2026 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> - 2.7.12-1
- Update to 2.7.12 rhbz#2445950
* Sat Jan 24 2026 Michael Kuhn <suraia(a)fedoraproject.org> - 2.7.11-3
- Add conditional recommends for wl-clipboard
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.7.11-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Mon Nov 24 2025 Germano Massullo (Thetra) <germano.massullo(a)thetra.eu> - 2.7.11-1
- 2.7.11 release
- Add org.keepassxc.KeePassXC.appdata.xml.patch
* Sun Nov 16 2025 Germano Massullo (Thetra) <germano.massullo(a)thetra.eu> - 2.7.10-6
- Replace botan2 with botan3 on EPEL>=10
* Tue Nov 11 2025 Germano Massullo (Thetra) <germano.massullo(a)thetra.eu> - 2.7.10-5
- Replace botan2 with botan3 on Fedora>=44
* Tue Nov 4 2025 Jan Grulich <jgrulich(a)redhat.com> - 2.7.10-4
- Rebuild (qt5)
* Thu Jul 24 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.7.10-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon May 26 2025 Jan Grulich <jgrulich(a)redhat.com> - 2.7.10-2
- Rebuild (qt5)
--------------------------------------------------------------------------------
================================================================================
python-configargparse-1.7.5-1.el9 (FEDORA-EPEL-2026-ed56d85d49)
Replacement for argparse that allows options to be set via config files
--------------------------------------------------------------------------------
Update Information:
1.7.5
Slightly simplified PyPI deployment workflow via setuptools-scm.
1.7.4
Bug Fixes
Fix environment variables being ignored when using subparsers. The
_find_insertion_index() method now detects subparser commands and inserts env
var / config file args before the subcommand, so the parent parser processes
them correctly.
Improvements
Add input validation to ArgumentParser.init() with clear error messages:
config_file_parser_class must be a ConfigFileParser subclass (or instance);
suggests formatter_class if wrong type is passed.
formatter_class validates it's a HelpFormatter subclass; suggests
config_file_parser_class if swapped.
default_config_file, args_for_setting_config_path, and
args_for_writing_out_config_file must be lists/tuples, not strings.
config_file_open_func must be callable.
Docs
Convert README from reStructuredText to Markdown
1.7.3
Bug fixes and Python 3.11+ tomllib support
Bug Fixes
Fix TOML parser to read all matching sections instead of only the first
Fix SyntaxError leak from ast.literal_eval in INI-style config parsers
Fix -- separator, nargs=REMAINDER, and empty value handling
Fix critical bugs and add Python 3.11+ tomllib support
Other
Remove dead comment-processing code in default config parser
Add test status badge to README
CI, linting, and test improvements
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 11 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 1.7.5-1
- Update to 1.7.5; close RHBZ#2446418
* Mon Mar 9 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 1.7.3-1
- Update to 1.7.3 (close RHBZ#2445572)
- Print reasons for skipped tests
* Mon Mar 9 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 1.7.1-2
- Confirm License is (SPDX) MIT
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2445572 - python-configargparse-1.7.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2445572
[ 2 ] Bug #2446418 - python-configargparse-1.7.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2446418
--------------------------------------------------------------------------------
================================================================================
rust-quick-xml-0.39.2-1.el9 (FEDORA-EPEL-2026-ae8be5c424)
High performance xml reader and writer
--------------------------------------------------------------------------------
Update Information:
Update the quick-xml crate to version 0.39.2 and add a compat package for
version 0.38.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 11 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.39.2-1
- Update to version 0.39.2; Fixes RHBZ#2428593
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.38.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-quick-xml0.38-0.38.4-1.el9 (FEDORA-EPEL-2026-ae8be5c424)
High performance xml reader and writer
--------------------------------------------------------------------------------
Update Information:
Update the quick-xml crate to version 0.39.2 and add a compat package for
version 0.38.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.38.4-1
- Initial import (quick-xml v0.38 compat package)
--------------------------------------------------------------------------------
================================================================================
tmt-1.69.0-1.el9 (FEDORA-EPEL-2026-076cf48931)
Test Management Tool
--------------------------------------------------------------------------------
Update Information:
Automatic update for tmt-1.69.0-1.el9.
Changelog for tmt
* Thu Mar 12 2026 Packit <hello(a)packit.dev> - 1.69.0-1
- Update to 1.69.0 upstream release
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Packit <hello(a)packit.dev> - 1.69.0-1
- Update to 1.69.0 upstream release
--------------------------------------------------------------------------------
================================================================================
wordpress-6.9.4-1.el9 (FEDORA-EPEL-2026-7fdbeef41b)
Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:
Upstream announcements:
WordPress 6.9.2 Release
WordPress 6.9.3 and 7.0 beta 4
WordPress 6.9.4 Release
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 12 2026 Remi Collet <remi(a)remirepo.net> - 6.9.4-1
- WordPress 6.9.4 Release
* Wed Mar 11 2026 Remi Collet <remi(a)remirepo.net> - 6.9.3-1
- WordPress 6.9.3 Release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2446479 - CVE-2026-3906 wordpress: WordPress: Unauthorized access to post notes via improper REST API permission check [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2446479
--------------------------------------------------------------------------------