nixpkgs/pkgs/servers/http
Malte Poll 7e537acfea envoy: 1.30.1 -> 1.30.2
Contains security fixes for:
- [CVE-2024-34362: Crash (use-after-free) in EnvoyQuicServerStream](GHSA-hww5-43gv-35jv)
- [CVE-2024-34363: Crash due to uncaught nlohmann JSON exception](GHSA-g979-ph9j-5gg4)
- [CVE-2024-34364: Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response, and other components](GHSA-xcj3-h7vf-fw26)
- [CVE-2024-32974: Crash in EnvoyQuicServerStream::OnInitialHeadersComplete()](GHSA-mgxp-7hhp-8299)
- [CVE-2024-32975: Crash in QuicheDataReader::PeekVarInt62Length()](GHSA-g9mq-6v96-cpqc)
- [CVE-2024-32976: Endless loop while decompressing Brotli data with extra input](GHSA-7wp5-c2vq-4f8m)
- [CVE-2024-23326: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode](GHSA-vcf8-7238-v74c)
2024-06-05 16:56:59 +02:00
..
angie treewide: remove unused fetchpatch arguments 2024-06-04 12:40:25 +02:00
apache-httpd
apache-modules pkgs/servers: remove licenses.gpl2 2024-05-23 11:49:42 +03:00
apt-cacher-ng
bozohttpd
cgiserver
couchdb
darkhttpd
dave
dufs dufs: 0.40.0 -> 0.41.0 2024-05-22 14:41:07 +00:00
envoy envoy: 1.30.1 -> 1.30.2 2024-06-05 16:56:59 +02:00
gatling pkgs/servers: remove licenses.gpl2 2024-05-23 11:49:42 +03:00
h2o
hiawatha pkgs/servers: remove licenses.gpl2 2024-05-23 11:49:42 +03:00
hyp
jboss
jetty jetty: 12.0.8 -> 12.0.9 2024-05-25 15:18:43 -04:00
lighttpd treewide: remove unused fetchpatch arguments 2024-06-04 12:40:25 +02:00
lwan pkgs/servers: remove licenses.gpl2 2024-05-23 11:49:42 +03:00
merecat
micro-httpd
mini-httpd
nginx treewide: remove unused fetchpatch arguments 2024-06-04 12:40:25 +02:00
nix-binary-cache
openresty
pomerium pomerium: 0.25.2 -> 0.26.0 2024-05-26 12:29:32 -05:00
pshs
quark
ran
redstore
router
showoff
spawn-fcgi
tengine
thttpd
tomcat tomcat10: 10.1.20 -> 10.1.23 2024-04-30 23:05:37 +02:00
trafficserver trafficserver: 9.2.3 -> 9.2.4 2024-04-11 07:37:19 +02:00
unit
webfs pkgs/servers: remove licenses.gpl2 2024-05-23 11:49:42 +03:00
webhook
yaws