-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 17:52:06 +0000 Source: nginx Binary: libnginx-mod-http-geoip libnginx-mod-http-geoip-dbgsym libnginx-mod-http-image-filter libnginx-mod-http-image-filter-dbgsym libnginx-mod-http-perl libnginx-mod-http-perl-dbgsym libnginx-mod-http-xslt-filter libnginx-mod-http-xslt-filter-dbgsym libnginx-mod-mail libnginx-mod-mail-dbgsym libnginx-mod-stream libnginx-mod-stream-dbgsym libnginx-mod-stream-geoip libnginx-mod-stream-geoip-dbgsym nginx nginx-dbgsym nginx-extras Architecture: arm64 Version: 1.26.3-3+deb13u4 Distribution: trixie Urgency: medium Maintainer: arm64 Build Daemon (arm-conova-04) Changed-By: Jan Mojžíš Description: libnginx-mod-http-geoip - GeoIP HTTP module for Nginx libnginx-mod-http-image-filter - HTTP image filter module for Nginx libnginx-mod-http-perl - Perl module for Nginx libnginx-mod-http-xslt-filter - XSLT Transformation module for Nginx libnginx-mod-mail - Mail module for Nginx libnginx-mod-stream - Stream module for Nginx libnginx-mod-stream-geoip - GeoIP Stream module for Nginx nginx - small, powerful, scalable web/proxy server nginx-extras - nginx web/proxy server (extended version) Changes: nginx (1.26.3-3+deb13u4) trixie; urgency=medium . * d/conf/*_params: use "$host" instead of "$http_host" * "$http_host" forwards the Host header exactly as supplied by the client and may not match the effective request target (e.g. absolute-form requests with a conflicting Host header) this can expose inconsistent or attacker-controlled host values to backend applications (uwsgi, fastcgi, scgi, proxy) * switch to "$host" as a safer, normalized alternative * note: this changes behaviour, as "$host" does not preserve the client-supplied port; deployments relying on "$http_host" including a port number may be affected * it is workaround for Debian bug #1126960 for stable/oldstable release Checksums-Sha1: d772904a0a25e629237b21834dc56345fb8328dc 38064 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_arm64.deb 6f4840be8b48dad3947006c2fd114ec2878b5bd1 88608 libnginx-mod-http-geoip_1.26.3-3+deb13u4_arm64.deb 5d1ce98caf4fca0d9d12754cc556907ea0291d45 45548 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_arm64.deb 5733a76aeb38dcbb4209fff71533575ddfc3f489 91900 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_arm64.deb 99cb1ba63e5a98d3d2816d653495e3e811407c64 108168 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_arm64.deb aeea0b09cac23727f0014b8c94768d1ed7c806e9 99872 libnginx-mod-http-perl_1.26.3-3+deb13u4_arm64.deb 06804c5ddd76d0dde6e1cdae7c1cd99ca3961166 54308 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_arm64.deb 91a00abdaafcb3f8af58a35542e876816555855b 90648 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_arm64.deb aaf1dd47afba3d7101ec902df4709ca949983e5d 103512 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_arm64.deb 735af1f2efccbca84a348846e8bd163bae7a2b7d 119852 libnginx-mod-mail_1.26.3-3+deb13u4_arm64.deb 4f70791c0125dd8b1bddf406952f24823ed710bb 182324 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_arm64.deb 6e7c005554d97da79b19fb09340bfd6555f07a01 24076 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_arm64.deb 19901c7ad62e25d9b665610d96557691514e14d9 87804 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_arm64.deb e8e179beff13c0d94e08348f3fd5a920ee10d123 148316 libnginx-mod-stream_1.26.3-3+deb13u4_arm64.deb 9b864dbc49eb12955813a769e67a13af96a068cc 1305432 nginx-dbgsym_1.26.3-3+deb13u4_arm64.deb f8b65fd452eb8c3b74fcef07fac3b7b43c3f5897 83980 nginx-extras_1.26.3-3+deb13u4_arm64.deb b980125de93c1f51793bb54fabf57cfe9d3adee7 13909 nginx_1.26.3-3+deb13u4_arm64-buildd.buildinfo e8a1065cb135e4f16204857f1060d3fe5608da95 568020 nginx_1.26.3-3+deb13u4_arm64.deb Checksums-Sha256: 88ccaf7948092a338acecff493e92cc666c7df28f5bafe2dac311c664aa47400 38064 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_arm64.deb 9102035f3780354cf52dc16406f1d9337b03ee0bdec69abf61979840b5e914d1 88608 libnginx-mod-http-geoip_1.26.3-3+deb13u4_arm64.deb 438def7b82b2e0c864414209ff34354d5103b6bdfc9058a9407cb75ad703748d 45548 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_arm64.deb 79fa73065ce1f76a3192beaa81e4fc69d21446b84740f003a72b44dc1b7e11d7 91900 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_arm64.deb 6c681a72b255034cdfcfd6058da1136b5e9f65e8f9ef4502af59d5774cddf17b 108168 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_arm64.deb 3a20b6b626ad68a25490a6cd4cdd55c3c2369e63ccf9156b9b115beec302935f 99872 libnginx-mod-http-perl_1.26.3-3+deb13u4_arm64.deb 0705096118004c146d636081eec3d2cf9c735c688abe6e48f802e00fb5998a70 54308 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_arm64.deb 9e3148b4d443febeaef8568f97e6f3e3c0877107b5bb83ec4ab9fdb485a2b319 90648 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_arm64.deb 4be984fd63059cd8292bb285918de8f6f0338b5d50f9a6725173613385c8f758 103512 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_arm64.deb bada900ed1771a04749cc44f690eeb24961a9706c84abcd3412ba3250fe98b8a 119852 libnginx-mod-mail_1.26.3-3+deb13u4_arm64.deb a027fc45312c4ac05273b305a6b7a303c34e07c4f272b6893bf3bb0f33329205 182324 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_arm64.deb b58d1a17371b8a50f7e22a6f31334e172a605414222e16a0790eaf51db63245a 24076 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_arm64.deb d08aa05d70bffeb8f7d6e349b7a51c395c087720c3f501bcaaca96787baf3008 87804 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_arm64.deb fb4e65fe36bc22a21a89fa928634ff648758e9d2404a9f3c654df874b7e9d917 148316 libnginx-mod-stream_1.26.3-3+deb13u4_arm64.deb 0df126982c225f31bbaf91e0b7b201873d3adfff1b71652d933ee5e3b317e829 1305432 nginx-dbgsym_1.26.3-3+deb13u4_arm64.deb ba566d0ee3d2106dbfffa15ae32c17e359ad455b320f7138d17d53088aaa14af 83980 nginx-extras_1.26.3-3+deb13u4_arm64.deb 51560cd7d9ae7ef8f5ff1b3cb9673905f8dabfd4014500857a1e39ab51ee33b2 13909 nginx_1.26.3-3+deb13u4_arm64-buildd.buildinfo 5d8a746f909b43c2e08ccbc3e8d70d6ed546cb8b76d8df22136ae7d27642cdb8 568020 nginx_1.26.3-3+deb13u4_arm64.deb Files: f8cae26e0fe10183d2505847b7f63739 38064 debug optional libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_arm64.deb cd34f65417813a1183a130e1e0495b29 88608 httpd optional libnginx-mod-http-geoip_1.26.3-3+deb13u4_arm64.deb 2e1af4f405c6ff6a0b4a6702275797c7 45548 debug optional libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_arm64.deb 6e7b162643c48193b9ea491392cdd8ac 91900 httpd optional libnginx-mod-http-image-filter_1.26.3-3+deb13u4_arm64.deb 072bf23d706b1b401d84b39ff76a1447 108168 debug optional libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_arm64.deb bc44288fd5fa827a8370559eddf8fd39 99872 httpd optional libnginx-mod-http-perl_1.26.3-3+deb13u4_arm64.deb a32f7657ee926f76477019ba4a445fd1 54308 debug optional libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_arm64.deb 6cd4cd5e9b9e377bee29ac19a0906411 90648 httpd optional libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_arm64.deb aed1ea9b0b34a1a65237353054f29daf 103512 debug optional libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_arm64.deb d7ef704fc0ffad5e7f2e059df4a76217 119852 httpd optional libnginx-mod-mail_1.26.3-3+deb13u4_arm64.deb 891a82766423994a50bd3e57f0bfc06a 182324 debug optional libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_arm64.deb 463f03f5b483ec15a37fa0fb60e6e249 24076 debug optional libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_arm64.deb f4d2c19a013310d5eb7fc0e9e939a985 87804 httpd optional libnginx-mod-stream-geoip_1.26.3-3+deb13u4_arm64.deb ec83d5f48f8c501c455c1b2cd0f775be 148316 httpd optional libnginx-mod-stream_1.26.3-3+deb13u4_arm64.deb eb42e821784ab20f5ca1635eccd59676 1305432 debug optional nginx-dbgsym_1.26.3-3+deb13u4_arm64.deb 74a166672ba6718624c2df1f3029a85f 83980 httpd optional nginx-extras_1.26.3-3+deb13u4_arm64.deb 63660dd58086e9904cce79011eb50aab 13909 httpd optional nginx_1.26.3-3+deb13u4_arm64-buildd.buildinfo 09b58f120e5afb7bb21a917f2b72e306 568020 httpd optional nginx_1.26.3-3+deb13u4_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmn5FvIACgkQScpU3dYu lLgCww/9FxAFKccWipuawNdmBYBeijdVSqIuHJP15SLfWfOWfFoUh0VgmECgGJHX tsP3w4jUNwTO9CPKJGrh1RWgmuhZ2PwiNWADL8of6+KwpIqGeC9Squvmn73qD8fN GnVtE5TW3RHGatqsZ/SgePMTqj1Pj+F6cmHACTdalIqqAEQ+G9ns+4sKe3pBkz9h IMH3t4cm2lIaQktyjOlPT4U1iTocs9gmjWgKNaUgFw2tyMJCFQaB2zTdMYO0EzOl qXbpK3WNyZOkR55xjGuCL3Oeieto8wjVD5tpsJWkL8Xz63jifsd/alvFMtS0m5NH Gi139o24S/NA4zLyp+0g/e1mY+ZSs3sMD1OzQxDDLiHue7ZaMclebPFBIPOKDkJt tYjNrTb7yzGtUaH3rLSW0/Az3wQlgCM8A/j86qEPH0V7l6laIaUlJEX3AI7p31xJ 7R+ySfGJHIeoOCVvNMP88rQhWoex0PauzXoNbKHL86+fopGcDwIARgtDjI2LczBc v09+LkSGAIpSWaJLfJIuQKRM0y+B1lbbtg4cHYCj8mYSYbjrJalKvPTuBsZ0YCdd NHlKj3eO9+HOAGtiHEYK6egpX51i4iC81QN7iHqlkGwELjgVlNiyqniPx0MzfROi BbnkWkcAYsxnVqD5T+TB8wTg7TFLWSOQLfkHehfj0BJ2hL/FLR8= =50VR -----END PGP SIGNATURE-----