- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- David Prévot
- Date:
- 2026-07-14 19:11:03 UTC
- Severity:
- normal
- Tags:
Hi, As agreed with the security team, I’d like to fix CVE-2026-55766 in the point release since it doesn’t deserve a DSA. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Thanks in advance for considering. Regards, taffit
Hi, Please go ahead. Thanks,
package release.debian.org tags 1140425 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: php-guzzlehttp-psr7 Version: 2.7.1-1+deb13u2 Explanation: fix CRLF injection in HTTP start-line parsing [CVE-2026-55766]
package release.debian.org tags 1140425 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: php-guzzlehttp-psr7 Version: 2.7.1-1+deb13u2 Explanation: fix CRLF injection in HTTP start-line parsing [CVE-2026-55766]