Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 42 yt-dlp Critical Command Injection Risk Fix 2026-7d3c7180c7

fedora
Calendar Grey March 5, 2026
Dist Fedora Esm H88
Fedora 42 update to yt-dlp fixes and mitigates significant vulnerabilities. Stay secure with latest patch.
Update to 2026.02.21

Summary

yt-dlp is a command-line program to download videos from many different online

video platforms, such as youtube.com. The project is a fork of youtube-dl with

additional features and fixes.

Update Information:

Update to 2026.02.21. Fixes rhbz#2441709. Mitigates CVE-2026-26331 / GHSA-g3gw-q23r-pgqm (rhbz#2442244)

Change Log

* Tue Feb 24 2026 Maxwell G - 2026.02.21-1 - Update to 2026.02.21. Fixes rhbz#2441709. - Mitigates CVE-2026-26331 / GHSA-g3gw-q23r-pgqm (rhbz#2442244) * Sat Feb 21 2026 Dominik 'Rathann' Mierzejewski - 2026.02.04-2 - fix FTBFS with python 3.14.3

References


[ 1 ] Bug #2441709 - yt-dlp-2026.02.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2441709 [ 2 ] Bug #2442244 - CVE-2026-26331 yt-dlp: yt-dlp: Arbitrary command injection via maliciously crafted URL when --netrc-cmd is used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2442244

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7d3c7180c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: yt-dlp
Product: Fedora 42
Version: 2026.02.21
Release: 1.fc42
Summary: A command-line program to download videos from online video platforms

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here