-
Wed Jul 29 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 8.12.1-4.4
- fix proxy environment variable change detection (CVE-2026-8927)
-
Wed Jul 22 2026 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-4.el10_2.3
- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)
- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)
- fix proxy connection reuse with wrong credentials (CVE-2026-3784)
-
Mon Jul 13 2026 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-4.2
- fix SSH host key mismatch on type difference (CVE-2026-9547)
- fix schemeless URL handling with --proto-default (CVE-2026-12064)
- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)
-
Mon Apr 20 2026 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-4.1
- openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)
-
Mon Nov 17 2025 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-4
- openssl: respect system crypto policy for TLS max version (RHEL-128916)
-
Mon Oct 20 2025 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-3
- cookie: don't treat the leading slash as trailing (CVE-2025-9086)
Resolves: RHEL-121672
-
Tue Apr 15 2025 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-2
- revert using tls-ca-bundle.pem instead of ca-bundle.crt (RHEL-56966)
(temporary revert to workaround another issue RHEL-85608)
-
Wed Mar 19 2025 Jacek Migacz <jmigacz@redhat.com> - 8.12.1-1
- new upstream release (RHEL-84132)
-
Tue Nov 05 2024 Jacek Migacz <jmigacz@redhat.com> - 8.9.1-6
- use tls-ca-bundle.pem instead of ca-bundle.crt (RHEL-56966)
-
Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 8.9.1-5
- Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018