-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 17:52:06 +0000 Source: nginx Binary: libnginx-mod-http-geoip libnginx-mod-http-geoip-dbgsym libnginx-mod-http-image-filter libnginx-mod-http-image-filter-dbgsym libnginx-mod-http-perl libnginx-mod-http-perl-dbgsym libnginx-mod-http-xslt-filter libnginx-mod-http-xslt-filter-dbgsym libnginx-mod-mail libnginx-mod-mail-dbgsym libnginx-mod-stream libnginx-mod-stream-dbgsym libnginx-mod-stream-geoip libnginx-mod-stream-geoip-dbgsym nginx nginx-dbgsym nginx-extras Architecture: amd64 Version: 1.26.3-3+deb13u4 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Jan Mojžíš Description: libnginx-mod-http-geoip - GeoIP HTTP module for Nginx libnginx-mod-http-image-filter - HTTP image filter module for Nginx libnginx-mod-http-perl - Perl module for Nginx libnginx-mod-http-xslt-filter - XSLT Transformation module for Nginx libnginx-mod-mail - Mail module for Nginx libnginx-mod-stream - Stream module for Nginx libnginx-mod-stream-geoip - GeoIP Stream module for Nginx nginx - small, powerful, scalable web/proxy server nginx-extras - nginx web/proxy server (extended version) Changes: nginx (1.26.3-3+deb13u4) trixie; urgency=medium . * d/conf/*_params: use "$host" instead of "$http_host" * "$http_host" forwards the Host header exactly as supplied by the client and may not match the effective request target (e.g. absolute-form requests with a conflicting Host header) this can expose inconsistent or attacker-controlled host values to backend applications (uwsgi, fastcgi, scgi, proxy) * switch to "$host" as a safer, normalized alternative * note: this changes behaviour, as "$host" does not preserve the client-supplied port; deployments relying on "$http_host" including a port number may be affected * it is workaround for Debian bug #1126960 for stable/oldstable release Checksums-Sha1: 7a6f03a0a02c98aa7d84c7462c6bd461dd6d9601 38084 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_amd64.deb 7b7ce0be0c2aa64de7b0c975935384933b2d08ad 88536 libnginx-mod-http-geoip_1.26.3-3+deb13u4_amd64.deb 89ff0a5029a40113a651dc5ff08977083c38fe56 46396 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_amd64.deb 68827ea4c71614d38cacaed258ba94973440dbe2 92276 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_amd64.deb 94b58e9d93cd6f7182fdb448d583ab4012e6ef81 109640 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_amd64.deb b82ad2a19a22ea32193726c517eef46ef6976e32 100780 libnginx-mod-http-perl_1.26.3-3+deb13u4_amd64.deb 9471649dd6ace0091c3cdd1c6cc940a6f9677490 54404 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_amd64.deb 53cefaf0ac863e390c82c88c60c667875a378e21 90756 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_amd64.deb a49fbd2b5674d1fda5a810e7a64a16023afe3e12 105080 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_amd64.deb 9a848b206aace6eb48219887d96199db55f56140 122584 libnginx-mod-mail_1.26.3-3+deb13u4_amd64.deb ddf3df082fb294fa29f2ad316d547cb945f01c4a 185808 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_amd64.deb ec9432f47e9dd40632d019a74cbff2214ac1ee44 24016 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_amd64.deb 7202e7ab2a8ab3b6500b95268d38af88e8b12755 87780 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_amd64.deb 6e3a9c3427c1a2ce18b88996d01b34c9b8730168 152664 libnginx-mod-stream_1.26.3-3+deb13u4_amd64.deb cede989cc93ec5b633c367f50fe360b17e575ee5 1342364 nginx-dbgsym_1.26.3-3+deb13u4_amd64.deb bddb19d076430159b5c97909a6d175835144daa7 83980 nginx-extras_1.26.3-3+deb13u4_amd64.deb eb992a20718a3d49520ab7ac0d9100044dd729e5 13925 nginx_1.26.3-3+deb13u4_amd64-buildd.buildinfo cce4a0213d6797cf4f5d298d89c586ef40c67811 609848 nginx_1.26.3-3+deb13u4_amd64.deb Checksums-Sha256: 06f8d4d82ab11aac38928b700358a1ae904a0c0cfb04aa5fcf9ce81f95f9370f 38084 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_amd64.deb 40912d22e09ae36d82fd4f98935fa419c73b59e6311290e072e1bc2593d5e2a5 88536 libnginx-mod-http-geoip_1.26.3-3+deb13u4_amd64.deb 4e625f3d8edc7eb6749dbca51f3fb0e8931fa5bbefa7ea62290cc1b88fb86c88 46396 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_amd64.deb 18e7075e2a93ed17cc56203e61fde56ebb0014648e23fddbc6c4ced6d56b060b 92276 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_amd64.deb e46b64e5d1830a6d7a87a0a069e328a346f5438fc5bb4586ff67a8d3d04b7963 109640 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_amd64.deb 79f5ec4248a70c60150119dcacba6abf0518e8a532c9d7a3317ec64696601c36 100780 libnginx-mod-http-perl_1.26.3-3+deb13u4_amd64.deb 8779dabafe823a61c96d99f81a423b011a16db7ea2004e0079a4c6544ea7af69 54404 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_amd64.deb e4e39b06489c8d953f60262c8218d9d7a4e7749c2aa82dc0179b4f4bff75e43c 90756 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_amd64.deb d7304afaf99ed7c62af2e1778f37cde3093739adfe254d9ca09f85f4145a90e8 105080 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_amd64.deb 929121c92cde5985d4cfcb1c36453818009d058d9869e57a148d9455e88692da 122584 libnginx-mod-mail_1.26.3-3+deb13u4_amd64.deb 1ef89c74e5d83f68c8b8d851954623e3eea328929d0905ead4766a37a0bab488 185808 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_amd64.deb f2410697d8c9f220817dd93f3c2ba50b402f635f2f3376e90e659a3b898256a6 24016 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_amd64.deb c912f70e9a41055545b97f6b253352103cb241ae05d85b21413c99af218e3212 87780 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_amd64.deb b8743af9b2c1c4920a121967bf38ec3f5c7f01faf3360377f838fa2ca4b07407 152664 libnginx-mod-stream_1.26.3-3+deb13u4_amd64.deb a09e95bbf10f0175b5eefd6ffaea29d01f6104d09628dcfa6b86865ed39e0a81 1342364 nginx-dbgsym_1.26.3-3+deb13u4_amd64.deb 46d4cae8b66ab90c3280ea6276ec5d110ec89e16786a62d5d74ef3197978706e 83980 nginx-extras_1.26.3-3+deb13u4_amd64.deb 8a0a84174c20c17cfebac0e8d41b3c7aa0ee2c8519603b2052917fcefb20eeb9 13925 nginx_1.26.3-3+deb13u4_amd64-buildd.buildinfo 6c9f919532c05c33ed709ea5d22dcacc7fe5d5a697df90abfac569c230070e2a 609848 nginx_1.26.3-3+deb13u4_amd64.deb Files: 037ce017608531863eb0c2c52cc0d459 38084 debug optional libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_amd64.deb 8ae4629b9274e63a8c9476dc9d549b65 88536 httpd optional libnginx-mod-http-geoip_1.26.3-3+deb13u4_amd64.deb 3fd2ef2b97f4c860653ee7997aafa160 46396 debug optional libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_amd64.deb 3b3f8ecdad660e1c84be071357837bfb 92276 httpd optional libnginx-mod-http-image-filter_1.26.3-3+deb13u4_amd64.deb 73d3ad638414239966d5ab4a7d323e9d 109640 debug optional libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_amd64.deb b4cab9205f0cef093c73924e50e1705e 100780 httpd optional libnginx-mod-http-perl_1.26.3-3+deb13u4_amd64.deb cc88c9dbed874c1265d31e36fd59b394 54404 debug optional libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_amd64.deb 851ee12d7dd3d92c7e67ee640f987a67 90756 httpd optional libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_amd64.deb 9ebbf1a8d832c4776334f688706af534 105080 debug optional libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_amd64.deb 3f031adcc5b6b55909478238a5703229 122584 httpd optional libnginx-mod-mail_1.26.3-3+deb13u4_amd64.deb a3864414aeda80fea7b227aafab6e085 185808 debug optional libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_amd64.deb 7839bb115db38f5331e58bc278dea4b6 24016 debug optional libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_amd64.deb 4875a63dc76aa72cef92b5709ef4481a 87780 httpd optional libnginx-mod-stream-geoip_1.26.3-3+deb13u4_amd64.deb 60532cf0e259da86b552becca8ca5569 152664 httpd optional libnginx-mod-stream_1.26.3-3+deb13u4_amd64.deb 8d896f873a210f34fc04994c63bfa8f1 1342364 debug optional nginx-dbgsym_1.26.3-3+deb13u4_amd64.deb 268a527ec330316dc124dafb0df93f0a 83980 httpd optional nginx-extras_1.26.3-3+deb13u4_amd64.deb 925be6f3488ac0449786ac91053e43b1 13925 httpd optional nginx_1.26.3-3+deb13u4_amd64-buildd.buildinfo d68ac7e524d9c9d002a8005b0a425706 609848 httpd optional nginx_1.26.3-3+deb13u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmn5FtoACgkQN8Ugyu9d QiS04A//aS6OnkGJJ9cirO0MY9eP+CfqxqZeI0YtWa6YNxblxxjvcn4rFJpv9flj r4AgUP82ONx1ilTLl4eoq11F/Vuat9dXED4FH4I5YCUYxaIgYx/MRw/gypU6bvBD MVsXaYN3dSajoWsyQmW8HiWH4gQ2EuaGEia1N9mJBrQxFjpr+aQN5yXM/tS7zRQd bofK+/t16n+Az0tTmy1d7VAyMXo/+ZLYSV+BpsM0uN/YCbDesjJaZOkJ67vMHLb/ iCHJ9NYwKONheHm6Wn8QEmHhz4Ym9rwMZ+0LTm2JpbImziHTpErbMwca5eH9KHSm yUjZT4bLg1ai1rKCVl/yDxoQ7P4bQJZ00ZlcQ3W4jNWJvTRzNWdiy2iglr3iTVew 6zMyCF32g3ReDk2O3oAnSpX41/MRD7/z+AxTBiZskhlApSFkUASSRnOgn/1TbE8a pntEHoOKgmaK9QgbEhGyq22/o+EzEevteCbBy4a8aJrSlP1/Yc0qv/vDJs1znfFo 9/n/fRKiQO9V1jzH5lnInV46KWdIYDaX+j3sGoEUm5GOYFedtT5uzFlLrFajhDCc qqxS8+4a9kSJZhIPRI6d9ReUKFn915hkmfmFEuUnksOY6lhEPloFCInl0/HkuLN0 tQGbSYv8XgKCEfvbOiQGIUvQBIHVZd01qBBNfucdyZps/AoVr84= =5zdv -----END PGP SIGNATURE-----