-
Thu Jul 23 2026 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-40.el9_8.5
- fix missing %patch macros for Patch46 and Patch47
-
Wed Jul 22 2026 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-40.el9_8.4
- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)
- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)
- tests: disable flaky test 1206 on x86_64 (FTP PORT timeout under valgrind)
-
Tue Jul 14 2026 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-40.3
- tests: disable flaky tests 3000, 3001 on i686 (stunnel startup race)
-
Mon Jul 13 2026 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-40.1
- fix SSH host key mismatch on type difference (CVE-2026-9547)
- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)
-
Wed Jan 21 2026 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-40
- openssl: fix libssh compatibility by preserving original SSL_CTX behavior (RHEL-134721)
-
Thu Dec 18 2025 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-39
- openssl: fix libssh compatibility in crypto-policy patch (RHEL-134721)
-
Mon Dec 01 2025 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-38
- http: fix crash in rate-limited upload (RHEL-131696)
-
Thu Nov 27 2025 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-37
- openssl: respect system crypto policy for TLS max version (RHEL-128914)
-
Thu Nov 20 2025 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-36
- rebuild for c9s (RHEL-125838)
-
Thu Oct 23 2025 Jacek Migacz <jmigacz@redhat.com> - 7.76.1-35
- cookie: don't treat the leading slash as trailing (CVE-2025-9086)
Resolves: RHEL-121659