-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-12765c0719 2026-06-17 08:41:51.002407+00:00 --------------------------------------------------------------------------------
Name : perl-Protocol-HTTP2 Product : Fedora 44 Version : 1.13 Release : 1.fc44 URL : https://metacpan.org/release/Protocol-HTTP2 Summary : HTTP/2 protocol implementation (RFC 7540) Description : Protocol::HTTP2 is Perl HTTP/2 protocol implementation (RFC 7540) with stateful decoders/encoders of HTTP/2 frames. You may use this module to implement your own HTTP/2 client/server/intermediate on top of your favorite event loop over plain or TLS socket.
-------------------------------------------------------------------------------- Update Information:
This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples. -------------------------------------------------------------------------------- ChangeLog:
* Mon Jun 8 2026 Petr Pisar ppisar@redhat.com - 1.13-1 - 1.13 bump -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2485660 - CVE-2026-10725 Protocol::HTTP2: Protocol::HTTP2: Denial of Service via HTTP/2 Bomb https://bugzilla.redhat.com/show_bug.cgi?id=2485660 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-12765c0719' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------