#1140425 trixie-pu: package php-guzzlehttp-psr7/2.7.1-1+deb13u2

#1140425#5
Date:
2026-06-20 07:45:47 UTC
From:
To:
Hi,

As agreed with the security team, I’d like to fix CVE-2026-55766 in the
point release since it doesn’t deserve a DSA.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Thanks in advance for considering.

Regards,

taffit

#1140425#12
Date:
2026-07-13 21:23:48 UTC
From:
To:
Hi,

Please go ahead.

Thanks,

#1140425#19
Date:
2026-07-14 19:09:26 UTC
From:
To:
package release.debian.org
tags 1140425 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: php-guzzlehttp-psr7
Version: 2.7.1-1+deb13u2

Explanation: fix CRLF injection in HTTP start-line parsing [CVE-2026-55766]

#1140425#24
Date:
2026-07-14 19:09:26 UTC
From:
To:
package release.debian.org
tags 1140425 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: php-guzzlehttp-psr7
Version: 2.7.1-1+deb13u2

Explanation: fix CRLF injection in HTTP start-line parsing [CVE-2026-55766]