Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 43 yt-dlp Important Command Injection Fix in FEDORA-2026-d86b88630b

fedora
Calendar Grey February 25, 2026
Dist Fedora Esm H88
Security advisory for yt-dlp in Fedora 43 mitigates critical command injection risk. Update recommended to secure systems.
Update to 2026.02.21

Summary

yt-dlp is a command-line program to download videos from many different online

video platforms, such as youtube.com. The project is a fork of youtube-dl with

additional features and fixes.

Update Information:

Update to 2026.02.21. Fixes rhbz#2441709. Mitigates CVE-2026-26331 / GHSA-g3gw-q23r-pgqm (rhbz#2442244)

Change Log

* Tue Feb 24 2026 Maxwell G - 2026.02.21-1 - Update to 2026.02.21. Fixes rhbz#2441709. - Mitigates CVE-2026-26331 / GHSA-g3gw-q23r-pgqm (rhbz#2442244) * Sat Feb 21 2026 Dominik 'Rathann' Mierzejewski - 2026.02.04-2 - fix FTBFS with python 3.14.3

References


[ 1 ] Bug #2441709 - yt-dlp-2026.02.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2441709 [ 2 ] Bug #2442244 - CVE-2026-26331 yt-dlp: yt-dlp: Arbitrary command injection via maliciously crafted URL when --netrc-cmd is used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2442244

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d86b88630b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: yt-dlp
Product: Fedora 43
Version: 2026.02.21
Release: 1.fc43
Summary: A command-line program to download videos from online video platforms

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here