Hi, The following vulnerability was published for aria2. CVE-2026-8367[0]: | aria2c accepts a server certificate with incorrect Extended Key | Usage (EKU). If the attackers compromise a certificate (with the | associated private key) issued for a different purpose, they may be | able to reuse it for TLS server authentication. https://github.com/aria2/aria2/issues/2355 If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-8367 https://www.cve.org/CVERecord?id=CVE-2026-8367 Please adjust the affected versions in the BTS as needed.