Skip to content

v1.2.1 - Security and Dependency Updates

Choose a tag to compare

@owine owine released this 05 Feb 22:04
· 143 commits to main since this release
d9e5323

Security Updates

This release addresses critical security vulnerabilities in OpenSSL:

Fixed CVEs

  • CVE-2026-22795 - Missing ASN1_TYPE validation in PKCS#12 parsing
  • CVE-2026-22796 - ASN1_TYPE Type Confusion in PKCS7_digest_from_attributes()
  • CVE-2025-15467 - Stack buffer overflow in CMS AuthEnvelopedData parsing
  • CVE-2025-15468 - NULL dereference in SSL_CIPHER_find() on unknown cipher ID
  • CVE-2025-66199 - TLS 1.3 CompressedCertificate excessive memory allocation
  • CVE-2025-68160 - Heap out-of-bounds write in BIO_f_linebuffer on short writes

Dependency Updates

  • Alpine Linux: 3.23.2 → 3.23.3 (patch update)
  • OpenSSL: 3.5.4-r0 → 3.5.5-r0 (security fixes)
  • GitHub Actions: Updated to latest versions (CI/CD infrastructure)

Container Images

Multi-architecture images published to GitHub Container Registry:

# Pull by exact version (recommended for production)
docker pull ghcr.io/owine/nut-cgi:v1.2.1

# Pull latest v1.2.x patch
docker pull ghcr.io/owine/nut-cgi:v1.2

# Pull latest v1.x minor
docker pull ghcr.io/owine/nut-cgi:v1

# Pull latest
docker pull ghcr.io/owine/nut-cgi:latest

Supported architectures: linux/amd64, linux/arm64

What's Changed

Full Changelog: v1.2.0...v1.2.1


Upgrade Priority: High - Critical security fixes included