-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 17:52:06 +0000 Source: nginx Binary: libnginx-mod-http-geoip libnginx-mod-http-geoip-dbgsym libnginx-mod-http-image-filter libnginx-mod-http-image-filter-dbgsym libnginx-mod-http-perl libnginx-mod-http-perl-dbgsym libnginx-mod-http-xslt-filter libnginx-mod-http-xslt-filter-dbgsym libnginx-mod-mail libnginx-mod-mail-dbgsym libnginx-mod-stream libnginx-mod-stream-dbgsym libnginx-mod-stream-geoip libnginx-mod-stream-geoip-dbgsym nginx nginx-dbgsym nginx-extras Architecture: i386 Version: 1.26.3-3+deb13u4 Distribution: trixie Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Jan Mojžíš Description: libnginx-mod-http-geoip - GeoIP HTTP module for Nginx libnginx-mod-http-image-filter - HTTP image filter module for Nginx libnginx-mod-http-perl - Perl module for Nginx libnginx-mod-http-xslt-filter - XSLT Transformation module for Nginx libnginx-mod-mail - Mail module for Nginx libnginx-mod-stream - Stream module for Nginx libnginx-mod-stream-geoip - GeoIP Stream module for Nginx nginx - small, powerful, scalable web/proxy server nginx-extras - nginx web/proxy server (extended version) Changes: nginx (1.26.3-3+deb13u4) trixie; urgency=medium . * d/conf/*_params: use "$host" instead of "$http_host" * "$http_host" forwards the Host header exactly as supplied by the client and may not match the effective request target (e.g. absolute-form requests with a conflicting Host header) this can expose inconsistent or attacker-controlled host values to backend applications (uwsgi, fastcgi, scgi, proxy) * switch to "$host" as a safer, normalized alternative * note: this changes behaviour, as "$host" does not preserve the client-supplied port; deployments relying on "$http_host" including a port number may be affected * it is workaround for Debian bug #1126960 for stable/oldstable release Checksums-Sha1: 3fe2178535b1b475831177662b0e2ae52ed4b31c 37160 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_i386.deb 2f199a0a12e4c7193034f4baa8404dc9f1c9af66 88940 libnginx-mod-http-geoip_1.26.3-3+deb13u4_i386.deb 6470192dfdfaad275f42a010ccd314e0afcb6940 44828 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_i386.deb 7f5dafbb25cc3268bfa96511010ab4f99deebbbd 92716 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_i386.deb fcd4dc060ad1ed68447ec001e4bf6d710e510763 104408 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_i386.deb c0680b55e60a05d8a55c379c2ce39270b3e634d5 101996 libnginx-mod-http-perl_1.26.3-3+deb13u4_i386.deb 55fd50845786394883f6c66ca33610b231c49e94 53132 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_i386.deb bc63d6356e95bb5e1f1c99d89e8f8fd0f1c31ccb 91324 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_i386.deb cd39906aa670bfff85da64761b8c97559d125bc0 103132 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_i386.deb d7543d77b2e4cf2fb461a34a7b0a13ccaed1033c 125264 libnginx-mod-mail_1.26.3-3+deb13u4_i386.deb 7f87b73ce0b60c7f6bffd71c84d84fa9ef12bf20 173428 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_i386.deb 03ac614a767a224cd12e1ad3074f4a6054ad461e 23508 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_i386.deb 2de879c6fe303ff3fa80f91a40a7c3d04d587813 88092 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_i386.deb 665fa092112619657c30ae3908feb1abe8a252ec 159540 libnginx-mod-stream_1.26.3-3+deb13u4_i386.deb 1f024f450a12e8646d57f9f7946cebf260894a66 1220584 nginx-dbgsym_1.26.3-3+deb13u4_i386.deb 152f5089fb18e3966ba5b47d45a2b291827901db 83976 nginx-extras_1.26.3-3+deb13u4_i386.deb 03e4c55bdcfe0cbc93ff58e374af7923e748fac6 13781 nginx_1.26.3-3+deb13u4_i386-buildd.buildinfo be54959264101e07c52baf1b2d79f9b341f69f27 665144 nginx_1.26.3-3+deb13u4_i386.deb Checksums-Sha256: 16ed08ac8a3e0825f023d9fa9d2f6aec5e728c37a0e8fa0aed24010bdf1e1f82 37160 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_i386.deb 3f57a6c35362a275f2e64375cb1b04344c48f225d9dab5a6105dcdf9990c5ced 88940 libnginx-mod-http-geoip_1.26.3-3+deb13u4_i386.deb df6d2b548caa1bc874465d2b3dc25f66e05436a42ba69f9e60f3721e92d2fd23 44828 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_i386.deb e7bd49ece547e092406a8b71f13034211e1e9cd50d7602d0c9f2ec2ca77bb3d5 92716 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_i386.deb a253582ae01570ead41f8b0c3ba72bd2077c4763d7405904d43254b476471f7a 104408 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_i386.deb e7161032bda5c9d09106bdb02387cd7a8232e73b4c4e2c01513bb63605115322 101996 libnginx-mod-http-perl_1.26.3-3+deb13u4_i386.deb e58bb16841080e6a9c60b5f81da8e57d1493f3fc28218a4e073a02c4db9a4030 53132 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_i386.deb ed42be08378ea382a476e18c2746e6cd1c949bb93724551ee1722266b5d1fcd1 91324 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_i386.deb 1b7a0beae3b162645e28c724d0ad81d3ff127a5654e6f5589dcfd43a52f7d8e8 103132 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_i386.deb 7a90675bd82bb2612e6744861352d8168b4153814cba28f9e53f5f9c0eed7435 125264 libnginx-mod-mail_1.26.3-3+deb13u4_i386.deb 8bf20854b6c01e55a896e894e09c774fc1dd62a76bc0f8a5ab2cf7f2e0a505da 173428 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_i386.deb 8b7c9076a535ff0afe86ba8a1300c4d1e16de05d6fe78764d768c5e3b860b413 23508 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_i386.deb 511715ca9ea70d2fdc6acb0fbe9cd87d5369deee3d41eaa2c033d980ba1dcd4b 88092 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_i386.deb f4448499abba40f4b1548a4e496556925eb999567273b05b82311424493f713b 159540 libnginx-mod-stream_1.26.3-3+deb13u4_i386.deb af0dd39cb36f31a0d7674208310d4c043aa838214991f4bed718953797a46807 1220584 nginx-dbgsym_1.26.3-3+deb13u4_i386.deb 82ef080e39250ccf76ec4e715d623e3955b1b3bd3ae5ae56f996836e1887ecce 83976 nginx-extras_1.26.3-3+deb13u4_i386.deb 370f5846ccae9b138801827c9f2f114499b8d161ff3b41cf9d166c21e12092c0 13781 nginx_1.26.3-3+deb13u4_i386-buildd.buildinfo a4314d32ca1031aa5cfcfff556eed552fb3fd3554f61f258ccc52cf077d8c068 665144 nginx_1.26.3-3+deb13u4_i386.deb Files: f6b4d0d08b9c351d1890836e6570a100 37160 debug optional libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_i386.deb 07552ad8cc4166f3f15411434bf0ed22 88940 httpd optional libnginx-mod-http-geoip_1.26.3-3+deb13u4_i386.deb 2399aa82d000d9bb1952bdc7e7485e58 44828 debug optional libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_i386.deb 97df1a3837d4aa71fe0d6922cf60c422 92716 httpd optional libnginx-mod-http-image-filter_1.26.3-3+deb13u4_i386.deb 8e5acec881cfe19c544101b4ed701022 104408 debug optional libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_i386.deb 79a459338806e25373c469800dd98107 101996 httpd optional libnginx-mod-http-perl_1.26.3-3+deb13u4_i386.deb 11cb7ad7ceefd464dc743c1b33f3a15c 53132 debug optional libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_i386.deb 1e65739d4de7da3342e5be0e58b629b6 91324 httpd optional libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_i386.deb 1842b209e74c9d7cf46abe05e80152e9 103132 debug optional libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_i386.deb 77ac281874edec6f0081e1c887e47ffe 125264 httpd optional libnginx-mod-mail_1.26.3-3+deb13u4_i386.deb 2272dbebc5609b4df662a368ab9f3de5 173428 debug optional libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_i386.deb 55e2541f931c5928d2c89860aa73077d 23508 debug optional libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_i386.deb ce3423bd0229024268518439c343e929 88092 httpd optional libnginx-mod-stream-geoip_1.26.3-3+deb13u4_i386.deb d8bd1926933f06917b79651bf83da0cb 159540 httpd optional libnginx-mod-stream_1.26.3-3+deb13u4_i386.deb 0bf5c0f36c05bde4510b7227bdca1888 1220584 debug optional nginx-dbgsym_1.26.3-3+deb13u4_i386.deb 57d6bbcaa797f135af8f3b233e734297 83976 httpd optional nginx-extras_1.26.3-3+deb13u4_i386.deb 6c597abea6a03f7aa642efd37f815823 13781 httpd optional nginx_1.26.3-3+deb13u4_i386-buildd.buildinfo 51eba93b4ecddc3db22b81fb1e202eb9 665144 httpd optional nginx_1.26.3-3+deb13u4_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmn5Fw4ACgkQTwt/65ON 6ze4Xg/9HoIEGV1o0cffHizsExeI3ZXHChK58dSYKuLtZISX4HqcvJQH+P5TQklm dq1+Jrzv9Z04eFtUM6M0rp1vHDggiPjZDW+EjNiyV8splhKDPbJZi65HROCFv9gp IOyi8XBBj2kJyYwwblQanYGRBSse4+tx7HkALxpgfl2VVUVWinTtktqj4EE/47ca 8Rhed40/SwA5EfgMfL00cWAvt0CoNucwlAIyM5F3TyMmxYAyMFVyiA8mzq0TSsil riVyTrLBSJk56wes07e2s/16GhrQ6doZjjgGmI6+Fug/mxe0F9NaOsAnPhCmGJNu A8RI8g4T8QECnkfcFhv3P0vkF+E3VZDj/y+f1vdy0ky/KAcAXo0nRg8uOuyErsVZ GrNTFrzTf8douFX3HHmrYd3MOlexibj999J+GtuZXC4WfHVMU+PHFdsTudljXgPD K/QBT7Uoyc23bwV5z48z/q0K2YW2P0o6Map0ZsvfjHIl18bxJz9toazuaF/CCN59 1GLffMehka18l2RAo9LNcuQ34mMKMJdJ5yB3A+WoIGZJp7htCDzw2if6q29TeiTK QbPGIFJi4BgPxNIdm6RCxiCTaasISk/1kEW8KiKvCwbovkcwKqA2VoRydPCy8fyE I9jH/3S+zljIDMclyNOMAiLdPSpfG2gpCcKdP+dlPI0kA34eHQA= =gDZx -----END PGP SIGNATURE-----