-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 17:52:06 +0000 Source: nginx Binary: libnginx-mod-http-geoip libnginx-mod-http-geoip-dbgsym libnginx-mod-http-image-filter libnginx-mod-http-image-filter-dbgsym libnginx-mod-http-perl libnginx-mod-http-perl-dbgsym libnginx-mod-http-xslt-filter libnginx-mod-http-xslt-filter-dbgsym libnginx-mod-mail libnginx-mod-mail-dbgsym libnginx-mod-stream libnginx-mod-stream-dbgsym libnginx-mod-stream-geoip libnginx-mod-stream-geoip-dbgsym nginx nginx-dbgsym nginx-extras Architecture: armhf Version: 1.26.3-3+deb13u4 Distribution: trixie Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-03) Changed-By: Jan Mojžíš Description: libnginx-mod-http-geoip - GeoIP HTTP module for Nginx libnginx-mod-http-image-filter - HTTP image filter module for Nginx libnginx-mod-http-perl - Perl module for Nginx libnginx-mod-http-xslt-filter - XSLT Transformation module for Nginx libnginx-mod-mail - Mail module for Nginx libnginx-mod-stream - Stream module for Nginx libnginx-mod-stream-geoip - GeoIP Stream module for Nginx nginx - small, powerful, scalable web/proxy server nginx-extras - nginx web/proxy server (extended version) Changes: nginx (1.26.3-3+deb13u4) trixie; urgency=medium . * d/conf/*_params: use "$host" instead of "$http_host" * "$http_host" forwards the Host header exactly as supplied by the client and may not match the effective request target (e.g. absolute-form requests with a conflicting Host header) this can expose inconsistent or attacker-controlled host values to backend applications (uwsgi, fastcgi, scgi, proxy) * switch to "$host" as a safer, normalized alternative * note: this changes behaviour, as "$host" does not preserve the client-supplied port; deployments relying on "$http_host" including a port number may be affected * it is workaround for Debian bug #1126960 for stable/oldstable release Checksums-Sha1: 21fdd81813acfb4a03deb3bcda7c138421dfe0a7 38368 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_armhf.deb 8937970d8575d846426b37c7ec6015af293ed6fe 87968 libnginx-mod-http-geoip_1.26.3-3+deb13u4_armhf.deb c80ea9cf3dc63e2214958633608cf928f6df490c 45824 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_armhf.deb 1a75b7ee7ac1b26f42b39752ee5e8587cae2c20a 91196 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_armhf.deb 07b2231c481b3742b1c1721ef8c637afa4c8e515 108408 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_armhf.deb 6504d9a2d385208896625aa4aba9637e15c259e9 98356 libnginx-mod-http-perl_1.26.3-3+deb13u4_armhf.deb de97f7a954c16d18d5b05b08752130a337268410 54496 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_armhf.deb fc08af4cfadf428d952302ab0262b47b7d807d78 89816 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_armhf.deb 934ee54134a2921b456f27a2fc60bb4d8a6008c4 110768 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_armhf.deb b118018f6c570a74ea05036975647ddba73d4d18 118080 libnginx-mod-mail_1.26.3-3+deb13u4_armhf.deb f86380cc1cb4585a0dec09aa2e6108e70996b80b 190824 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_armhf.deb fad590f0443ea32dbfe3c69ea4611577a5ba7762 24596 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_armhf.deb 22a8f5586ab55390e901c1a7196d790f90524bb5 87216 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_armhf.deb 9ef2f58d17c669a5bc7b6edb813b031ff527f2ae 142568 libnginx-mod-stream_1.26.3-3+deb13u4_armhf.deb 3ad2ac290ddc7670c5a6e127157324b73eee8770 1342820 nginx-dbgsym_1.26.3-3+deb13u4_armhf.deb f2bfb54ae035269ef9b81aa5aa072e6ef9bdba77 83980 nginx-extras_1.26.3-3+deb13u4_armhf.deb 4d331d2e51cb25391d0b1d4a1edff3d4f3eaf90e 13788 nginx_1.26.3-3+deb13u4_armhf-buildd.buildinfo 642731b48b6f2c9bd4503358ced947f0cbf8ca48 549120 nginx_1.26.3-3+deb13u4_armhf.deb Checksums-Sha256: 59409aca007e476ccbc279d6be8f0dd9924e472d55673fbb5f3233ded645ff99 38368 libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_armhf.deb 66226ba5ca40a9127840d25d2a81cad56ee7ab7330e15842c9437a296106bbc0 87968 libnginx-mod-http-geoip_1.26.3-3+deb13u4_armhf.deb 0176d8b80edc755b3ebcf2549df4ce46d315659df8ea3f32678d2aa70c89179b 45824 libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_armhf.deb bbc1f3cc6218beaeb0274ac7ee75dfa627d4cee9feef52f2dfb22e65c51427c6 91196 libnginx-mod-http-image-filter_1.26.3-3+deb13u4_armhf.deb 2317fd7fac78c4f6773ab7a480e80738b6f60ee32e3272d217e0dc5efa8b342d 108408 libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_armhf.deb 0c254538c32e8dd1ba45a821f5190c0770095c655f33f78eb7267f1c1ed96ae5 98356 libnginx-mod-http-perl_1.26.3-3+deb13u4_armhf.deb 5d9a50624b779937d0390a113466916a6c722ec15f42f28e66a67090a3f1c5fc 54496 libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_armhf.deb e7fdfb510338e7c7094639685f06183d2ffb1c8cc8dd59ced4ad553eed00343a 89816 libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_armhf.deb 52a3e09f631cb8e1502f5f0c39550f3d1215f618de9fb4b0c8673252a03ba81f 110768 libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_armhf.deb b8055e64a229ae45807d94c9dc16d49b0cc2c61171b382d69d2042ec5f007010 118080 libnginx-mod-mail_1.26.3-3+deb13u4_armhf.deb f558975bd0d880043e6d744233b9dca289d06b6305aac49998b7f8add725d803 190824 libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_armhf.deb 367cbe0e7fd64eef9ec5e071fdb521e5ff3de00e0a829dddb3733ff841fcf72d 24596 libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_armhf.deb 56f57b0d51fd692e1b4b6a6b24e3b5f3110ae2dcffd3e809f6abab2ffc8c014d 87216 libnginx-mod-stream-geoip_1.26.3-3+deb13u4_armhf.deb 92bfe6ea771e1667b932b26615e5c61db457502331108c724ed8167a6cbdf0ea 142568 libnginx-mod-stream_1.26.3-3+deb13u4_armhf.deb 399ef071e0a06df44f956460e607e6b394d57882edd1ff46a8f1251060337e1e 1342820 nginx-dbgsym_1.26.3-3+deb13u4_armhf.deb b945af08459fc8da2ba7c057c91c967b7b35b698f27c12e9c5e59333b3e92145 83980 nginx-extras_1.26.3-3+deb13u4_armhf.deb ed30042f90a3b5657ee32a9b1f93f9d1b64d71b574afc5da48b555cceb3377ff 13788 nginx_1.26.3-3+deb13u4_armhf-buildd.buildinfo 1df75049a8ae9eb11d3cbb8198f9b7404acc8203fbb3e8bb9ebaa4447de5416d 549120 nginx_1.26.3-3+deb13u4_armhf.deb Files: 07a20a89ced65d38df2c7227ba2acb19 38368 debug optional libnginx-mod-http-geoip-dbgsym_1.26.3-3+deb13u4_armhf.deb 4f9c015b8f5c48430b5aeb1f525cc187 87968 httpd optional libnginx-mod-http-geoip_1.26.3-3+deb13u4_armhf.deb 573119859906759b9725ec023a2f6287 45824 debug optional libnginx-mod-http-image-filter-dbgsym_1.26.3-3+deb13u4_armhf.deb 5f95a50e602edb49d38cb187575fb59f 91196 httpd optional libnginx-mod-http-image-filter_1.26.3-3+deb13u4_armhf.deb 06e844f8e936499f31a00eabd5fbe62e 108408 debug optional libnginx-mod-http-perl-dbgsym_1.26.3-3+deb13u4_armhf.deb 628b41f0da62e2d53a60f24c0fc6a79a 98356 httpd optional libnginx-mod-http-perl_1.26.3-3+deb13u4_armhf.deb 13f8db4f3ff0f150245ec76f78cb84ef 54496 debug optional libnginx-mod-http-xslt-filter-dbgsym_1.26.3-3+deb13u4_armhf.deb 924a6e7262448435f5ef620f4a2dca20 89816 httpd optional libnginx-mod-http-xslt-filter_1.26.3-3+deb13u4_armhf.deb f514b23651a4d8e433f70c9a188ce216 110768 debug optional libnginx-mod-mail-dbgsym_1.26.3-3+deb13u4_armhf.deb 58e0c3aceb596638edcdd6c3275f4abd 118080 httpd optional libnginx-mod-mail_1.26.3-3+deb13u4_armhf.deb 3116105726bf6f85dd88f39eed372854 190824 debug optional libnginx-mod-stream-dbgsym_1.26.3-3+deb13u4_armhf.deb 1d756b955196761b9f0452139be18950 24596 debug optional libnginx-mod-stream-geoip-dbgsym_1.26.3-3+deb13u4_armhf.deb 1f24fb510feee1e02f7de1c5cf955ea0 87216 httpd optional libnginx-mod-stream-geoip_1.26.3-3+deb13u4_armhf.deb db5ca45f58cb2f1c22b1a0e06aa1f279 142568 httpd optional libnginx-mod-stream_1.26.3-3+deb13u4_armhf.deb 44b5d28f73f61732e07eb1bdb0f3081d 1342820 debug optional nginx-dbgsym_1.26.3-3+deb13u4_armhf.deb 830ec93da5a6d1a2c0efeeea17828131 83980 httpd optional nginx-extras_1.26.3-3+deb13u4_armhf.deb bfab737c24c53d5a45f6c30b1d6e9833 13788 httpd optional nginx_1.26.3-3+deb13u4_armhf-buildd.buildinfo 256ca72ea07dfd8ea5f9a0b2e9cb771b 549120 httpd optional nginx_1.26.3-3+deb13u4_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE2kd8oHy+LXk/nybqvzDqKQSGl8UFAmn5FukACgkQvzDqKQSG l8Vs9g//etYS9aFnmnQTW69MRmwYNU0QtLXkokhRGByaYn0rTsFwwttJovSrWsNi kW5OejFb392WUSUfFUFfLaC/9u4/1E45eEcPd0Ve/zhk/IBDsHSIETlyHmewGfee dFHmYP6wham/H7o5xrDP7wddHuU9zep3QlYHFTgr2wK/Mi0iuiLv6qmiePMcqmgn RaDGiiopVhIxD1VmpZFpV74HB2HohtB82eG6O5dho+AUCUMA1TgOj0DMznys9p1K fKkwPR62FCXJTUM1DsBMuTswROVu0v7aw6TydhWa6KM/tJch8OuUazU4SPdKHLKs 1zArbssuzbzMfBnES7/nD0sD1Ctn3z4AtY5u5gEdZMs2rTv/X8zR19JZDTUZxB2r PCVV2XcxKGsOxozYl9V4H2H8uipmc0CsJiqKOdA1f040ZRHSkkOOrrzkpX9HgAPv d4KIuJxJwrlQIyGsushRmsgDS9aqmfoOPe7FJPosFCONIL0/g+wjTCJN8Mx/Rsfu 7uE59DA6cwI2JyoUxMbAgPkZGoRQ1UdCDFbkJTvz7T64vJE9jsaHj9UwVwy1/DxM hUwJRgnXTjkyVbOkrYq1YVi7aX+nn3PMeZ1Tl705AMEAl2lJeseWur5x+JUnjw+B ExVkWJr69rNVzMo+AQR50IUN11zT8iGjoEJZLKilzID9WIkTs68= =oCuu -----END PGP SIGNATURE-----