Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 44 Gum Critical CVE-2026-5160 Cross Site Scripting Issue Fix

fedora
Calendar Grey April 28, 2026
Dist Fedora Esm H88
Fedora 44 gum update fixes critical cross-site scripting issue by updating goldmark to 1.7.17. Immediate action required!
Update vendored goldmark to 1.7.17 to resolve CVE-2026-5160.

Summary

A tool for glamorous shell scripts. Leverage the power of Bubbles and Lip Gloss

in your scripts and aliases without writing any Go code!

Update Information:

Update vendored goldmark to 1.7.17 to resolve CVE-2026-5160.

Change Log

* Fri Apr 17 2026 Carl George - 0.17.0-3 - Update vendored goldmark to 1.7.17 to resolve CVE-2026-5160

References


[ 1 ] Bug #2458994 - CVE-2026-5160 gum: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458994

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-10cf6ce616' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: gum
Product: Fedora 44
Version: 0.17.0
Release: 3.fc44
Summary: Tool for glamorous shell scripts

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here