The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.
March 21, 2026
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186
March 21, 2026
Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)
March 21, 2026
Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
March 20, 2026
This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-
March 20, 2026
Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359
March 20, 2026
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski