nginx-mod-naxsi: Rebuild for 1.28.2 nginx-mod-brotli: Rebuild for 1.28.2 nginx-mod-fancyindex:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cd0705c6a7 2026-02-15 01:10:21.966685+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-brotli Product : Fedora 43 Version : 1.0.0~rc Release : 6.fc43 URL : https://github.com/google/ngx_brotli Summary : NGINX module for Brotli compression Description : NGINX module for Brotli compression. -------------------------------------------------------------------------------- Update Information: nginx-mod-naxsi: Rebuild for 1.28.2 nginx-mod-brotli: Rebuild for 1.28.2 nginx-mod-fancyindex: Rebuild for 1.28.2 nginx-mod-modsecurity: Rebuild for 1.28.2 nginx-mod-headers-more: Rebuild for 1.28.2 nginx-mod-vts: Rebuild for 1.28.2 nginx: Update to 1.28.2 fixes CVE-2026-1642 move log directory to nginx-filesystem subpackage (PR#20) delete Maxim Dounin's key, it's no longer listed on the nginx website -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 4 2026 Felix Kaechele - 1.0.0~rc-6 - Rebuild for 1.28.2 * Fri Jan 16 2026 Fedora Release Engineering - 1.0.0~rc-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2436871 - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2436871 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cd0705c6a7' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-2389 http://linux.oracle.com/errata/ELSA-2026-2389.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: brotli-1.0.6-4.el8_10.i686.rpm brotli-1.0.6-4.el8_10.x86_64.rpm brotli-devel-1.0.6-4.el8_10.i686.rpm brotli-devel-1.0.6-4.el8_10.x86_64.rpm python3-brotli-1.0.6-4.el8_10.x86_64.rpm aarch64: brotli-1.0.6-4.el8_10.aarch64.rpm brotli-devel-1.0.6-4.el8_10.aarch64.rpm python3-brotli-1.0.6-4.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/brotli-1.0.6-4.el8_10.src.rpm Related CVEs: CVE-2025-6176 Description of changes: [1.0.6-4] - Resolves: RHEL-133986 CVE-2025-6176 Brotli decompression bomb DoS in scrapy _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-2042 http://linux.oracle.com/errata/ELSA-2026-2042.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: brotli-1.0.9-9.el9_7.i686.rpm brotli-1.0.9-9.el9_7.x86_64.rpm brotli-devel-1.0.9-9.el9_7.i686.rpm brotli-devel-1.0.9-9.el9_7.x86_64.rpm libbrotli-1.0.9-9.el9_7.i686.rpm libbrotli-1.0.9-9.el9_7.x86_64.rpm python3-brotli-1.0.9-9.el9_7.x86_64.rpm aarch64: brotli-1.0.9-9.el9_7.aarch64.rpm brotli-devel-1.0.9-9.el9_7.aarch64.rpm libbrotli-1.0.9-9.el9_7.aarch64.rpm python3-brotli-1.0.9-9.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/brotli-1.0.9-9.el9_7.src.rpm Related CVEs: CVE-2025-6176 Description of changes: [1.0.9-9] - Resolves: RHEL-133995 Rebuild for CVE-2025-6176 Brotli decompression bomb DoS in scrapy [1.0.9-8] - Resolves: RHEL-133995 CVE-2025-6176 Brotli decompression bomb DoS in scrapy _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0845 http://linux.oracle.com/errata/ELSA-2026-0845.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: brotli-1.1.0-7.el10_1.x86_64.rpm brotli-devel-1.1.0-7.el10_1.x86_64.rpm libbrotli-1.1.0-7.el10_1.x86_64.rpm python3-brotli-1.1.0-7.el10_1.x86_64.rpm aarch64: brotli-1.1.0-7.el10_1.aarch64.rpm brotli-devel-1.1.0-7.el10_1.aarch64.rpm libbrotli-1.1.0-7.el10_1.aarch64.rpm python3-brotli-1.1.0-7.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/brotli-1.1.0-7.el10_1.src.rpm Related CVEs: CVE-2025-6176 Description of changes: [1.1.0-7] - Resolves: RHEL-133984 CVE-2025-6176 Brotli decompression bomb DoS in scrapy _______________________________________________ El-errata mailing list
Update brotli to 1.2.0. This update provides the necessary Python APIs in python3-brotli to fix denial- of-service security issues related to \u201cdecompression bombs,\u201d such as CVE-2025-66471 or CVE-2025-6176, but actually fixing them would require separate updates in affected packages.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9e233a4e22 2025-12-18 01:10:20.380939+00:00 -------------------------------------------------------------------------------- Name : brotli Product : Fedora 42 Version : 1.2.0 Release : 1.fc42 URL : https://github.com/google/brotli Summary : Lossless compression algorithm Description : Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression. -------------------------------------------------------------------------------- Update Information: Update brotli to 1.2.0. This update provides the necessary Python APIs in python3-brotli to fix denial- of-service security issues related to \u201cdecompression bombs,\u201d such as CVE-2025-66471 or CVE-2025-6176, but actually fixing them would require separate updates in affected packages. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 8 2025 Benjamin A. Beasley - 1.2.0-1 - Update to 1.2.0 (close RHBZ#2401888) - Stop trying to support EPEL7, which is end-of-life - Port to pyproject-rpm-macros (close RHBZ#2377212) - Test the Python extension * Fri Sep 19 2025 Python Maint - 1.1.0-10 - Rebuilt for Python 3.14.0rc3 bytecode * Fri Aug 15 2025 Python Maint - 1.1.0-9 - Rebuilt for Python 3.14.0rc2 bytecode * Wed Jul 23 2025 Fedora Release Engineering - 1.1.0-8 - Rebuiltfor https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Mon Jun 2 2025 Python Maint - 1.1.0-7 - Rebuilt for Python 3.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419491 - CVE-2025-6176 brotli: Brotli decompression bomb DoS in scrapy/scrapy [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419491 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9e233a4e22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . The update to brotli version 1.2.0 mitigates denial-of-service vulnerabilities and improves the Python API for better performance and security. brotli update, Fedora 42, denial of service, Python security. . Severity: Critical. LinuxSecurity.com Team
Update brotli to 1.2.0 and python-urllib3 to 2.6.1. In python-urllib3: Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d93200cf16 2025-12-12 01:32:22.209029+00:00 -------------------------------------------------------------------------------- Name : brotli Product : Fedora 43 Version : 1.2.0 Release : 1.fc43 URL : https://github.com/google/brotli Summary : Lossless compression algorithm Description : Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression. -------------------------------------------------------------------------------- Update Information: Update brotli to 1.2.0 and python-urllib3 to 2.6.1. In python-urllib3: Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small chunks of compressed data is safer and much more efficient now. (CVE-2025-66471 / `GHSA-2xpw-w6gg-jr37) Fixed a security issue where an attacker could compose an HTTP response with virtually unlimited links in the Content-Encoding header, potentially leading to a denial of service (DoS) attack by exhausting system resources during decoding. The number of allowed chained encodings is now limited to 5. (CVE-2025-66418 /`GHSA-gm62-xv2j-4w53) -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 8 2025 Benjamin A. Beasley - 1.2.0-1 - Update to 1.2.0 (close RHBZ#2401888) - Stop trying to support EPEL7, which is end-of-life - Port to pyproject-rpm-macros (close RHBZ#2377212) - Test the Python extension -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419408 - python-urllib3-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419408 [ 2 ] Bug #2419493 - CVE-2025-6176 brotli: Brotli decompression bomb DoS in scrapy/scrapy [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419493 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d93200cf16' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update brotli to 1.2.0 and python-urllib3 to 2.6.1. In python-urllib3: Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d93200cf16 2025-12-12 01:32:22.209029+00:00 -------------------------------------------------------------------------------- Name : perl-Alien-Brotli Product : Fedora 43 Version : 0.2.2 Release : 11.fc43 URL : http://metacpan.org/dist/Alien-Brotli Summary : Find and install the Brotli compressor Description : This distribution installs the brotli compressor, so that it can be used by other distributions, and provides a way to find the executable. -------------------------------------------------------------------------------- Update Information: Update brotli to 1.2.0 and python-urllib3 to 2.6.1. In python-urllib3: Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small chunks of compressed data is safer and much more efficient now. (CVE-2025-66471 / `GHSA-2xpw-w6gg-jr37) Fixed a security issue where an attacker could compose an HTTP response with virtually unlimited links in the Content-Encoding header, potentially leading to a denial of service (DoS) attack by exhausting system resources during decoding. The number of allowed chained encodings is now limited to 5. (CVE-2025-66418 / `GHSA-gm62-xv2j-4w53) -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 10 2025 Miro Hron\u010dok - 0.2.2-11 - Rebuilt for brotli 1.2.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug#2419408 - python-urllib3-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419408 [ 2 ] Bug #2419493 - CVE-2025-6176 brotli: Brotli decompression bomb DoS in scrapy/scrapy [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419493 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d93200cf16' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 addresses critical issues in Brotli and python-urllib3, including decompression bombs and DoS risks.. Fedora updates, python-urllib3 security, Brotli compression, critical security issues, DoS prevention. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # python311-Brotli-1.2.0-1.1 on GA media Announcement ID: openSUSE-SU-2025:15731-1 Rating: moderate Cross-References: * CVE-2025-6176 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python311-Brotli-1.2.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python311-Brotli 1.2.0-1.1 * python312-Brotli 1.2.0-1.1 * python313-Brotli 1.2.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6176.html . Python311 Brotli package update addresses moderate issues for openSUSE Tumbleweed, enhancing overall system security.. openSUSE Tumbleweed, python311-Brotli update, security advisory, threat mitigation, moderate severity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.