-
Tue Mar 31 2026 Jan Macku <jamacku@redhat.com> 1.68.0-3.1
- fix Denial of service: Assertion failure due to the missing state validation (CVE-2026-27135)
-
Wed Feb 11 2026 Jan Macku <jamacku@redhat.com> 1.68.0-3
- Spec bump (RHEL-103655)
-
Mon Feb 09 2026 Jan Macku <jamacku@redhat.com> 1.68.0-2
- PQC: make X25519MLKEM768 the default TLS key exchange group in nghttpd and nghttpx (RHEL-103655)
-
Mon Feb 09 2026 Jan Macku <jamacku@redhat.com> 1.68.0-1
- update to the latest upstream release (RHEL-143723)
-
Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 1.64.0-2
- Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018
-
Tue Oct 22 2024 Jan Macku <jamacku@redhat.com> 1.64.0-1
- update to the latest upstream release
-
Mon Sep 30 2024 Jan Macku <jamacku@redhat.com> 1.63.0-1
- update to the latest upstream release
-
Tue Aug 06 2024 Jan Macku <jamacku@redhat.com> 1.62.1-1
- update to the latest upstream release
-
Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 1.61.0-2
- Bump release for June 2024 mass rebuild
-
Thu Apr 04 2024 Jan Macku <jamacku@redhat.com> 1.61.0-1
- update to the latest upstream release
- fixes CVE-2024-28182 - HTTP/2 CONTINUATION frames can be utilized for DoS attacks