-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 22 Apr 2026 20:15:43 +0000 Source: nginx Binary: libnginx-mod-http-geoip libnginx-mod-http-geoip-dbgsym libnginx-mod-http-image-filter libnginx-mod-http-image-filter-dbgsym libnginx-mod-http-perl libnginx-mod-http-perl-dbgsym libnginx-mod-http-xslt-filter libnginx-mod-http-xslt-filter-dbgsym libnginx-mod-mail libnginx-mod-mail-dbgsym libnginx-mod-stream libnginx-mod-stream-dbgsym libnginx-mod-stream-geoip libnginx-mod-stream-geoip-dbgsym nginx nginx-dbgsym nginx-extras Architecture: armhf Version: 1.22.1-9+deb12u6 Distribution: bookworm Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-05) Changed-By: Jan Mojžíš Description: libnginx-mod-http-geoip - GeoIP HTTP module for Nginx libnginx-mod-http-image-filter - HTTP image filter module for Nginx libnginx-mod-http-perl - Perl module for Nginx libnginx-mod-http-xslt-filter - XSLT Transformation module for Nginx libnginx-mod-mail - Mail module for Nginx libnginx-mod-stream - Stream module for Nginx libnginx-mod-stream-geoip - GeoIP Stream module for Nginx nginx - small, powerful, scalable web/proxy server nginx-extras - nginx web/proxy server (extended version) Changes: nginx (1.22.1-9+deb12u6) bookworm; urgency=medium . * d/conf/*_params: use "$host" instead of "$http_host" * "$http_host" forwards the Host header exactly as supplied by the client and may not match the effective request target (e.g. absolute-form requests with a conflicting Host header) this can expose inconsistent or attacker-controlled host values to backend applications (uwsgi, fastcgi, scgi, proxy) * switch to "$host" as a safer, normalized alternative * note: this changes behaviour, as "$host" does not preserve the client-supplied port; deployments relying on "$http_host" including a port number may be affected * it is workaround for Debian bug #1126960 for stable/oldstable release Checksums-Sha1: 7d8ca1da76b544f5703ce5bbb0b2694edb72f22c 36888 libnginx-mod-http-geoip-dbgsym_1.22.1-9+deb12u6_armhf.deb 8bed12423909c807a0f801deac5b389eae95a5ae 84504 libnginx-mod-http-geoip_1.22.1-9+deb12u6_armhf.deb 5c0c80a8905ee2cfc2e56fa4de771b5d82891102 44280 libnginx-mod-http-image-filter-dbgsym_1.22.1-9+deb12u6_armhf.deb 017d1e1fad23d7fe5864b611c5ca7a4a895515e2 87912 libnginx-mod-http-image-filter_1.22.1-9+deb12u6_armhf.deb 5651260ce6a9d25ef88265a15569a799fa214c40 98708 libnginx-mod-http-perl-dbgsym_1.22.1-9+deb12u6_armhf.deb 2ad228417f311f1a700bd3bdd9cfbd51d0791298 94712 libnginx-mod-http-perl_1.22.1-9+deb12u6_armhf.deb d14f8b3af143d9db4da9c10be30ca57ab8cb86e8 53132 libnginx-mod-http-xslt-filter-dbgsym_1.22.1-9+deb12u6_armhf.deb 5750842932ef464e94460de8eee80b464ab1e2aa 86344 libnginx-mod-http-xslt-filter_1.22.1-9+deb12u6_armhf.deb 7fbfb31297214bc4f9cf83e4fd15d37dc14fd38a 110096 libnginx-mod-mail-dbgsym_1.22.1-9+deb12u6_armhf.deb 25c873099e93dac9c1af2e09f64f32eaa860fa73 114952 libnginx-mod-mail_1.22.1-9+deb12u6_armhf.deb 3bf2d7fd91e91992d5a5a8c6e218bc7222de09c1 175404 libnginx-mod-stream-dbgsym_1.22.1-9+deb12u6_armhf.deb 070ff81022ada26439cbe517cdccbfe5bd95db74 22712 libnginx-mod-stream-geoip-dbgsym_1.22.1-9+deb12u6_armhf.deb 2c42e40d3690c4aae9210808233a28c8d692bca6 83864 libnginx-mod-stream-geoip_1.22.1-9+deb12u6_armhf.deb 173f661b09104f7538ab2a65fe476bee419dcdc7 134872 libnginx-mod-stream_1.22.1-9+deb12u6_armhf.deb ec534519d335635bd9a41e1324a3ca12b22822e3 1117740 nginx-dbgsym_1.22.1-9+deb12u6_armhf.deb 5fd590551e69e05d6c1874c82a5e92407f831136 80812 nginx-extras_1.22.1-9+deb12u6_armhf.deb 51c316930f9758c1759f33f2b126905796170bca 14091 nginx_1.22.1-9+deb12u6_armhf-buildd.buildinfo bcb8bbf06975f32367793764e5ad67774802a9f7 472400 nginx_1.22.1-9+deb12u6_armhf.deb Checksums-Sha256: 39dbb103598b4784dc03cbcc4393906d124a2c0f3be59027d7c7e29678d91e29 36888 libnginx-mod-http-geoip-dbgsym_1.22.1-9+deb12u6_armhf.deb 273324715bbc6476913f980617483e96c8e9658bd78bbd5a404c03fe24bb81b7 84504 libnginx-mod-http-geoip_1.22.1-9+deb12u6_armhf.deb 8f8a25df4120f1ea2c31b194460b7300ae8486bf226f6869d5a832d98d34b0c7 44280 libnginx-mod-http-image-filter-dbgsym_1.22.1-9+deb12u6_armhf.deb c5413ec5136ea828567bf039914c40eb4dba38f9f9b265a93c21a0271ca90751 87912 libnginx-mod-http-image-filter_1.22.1-9+deb12u6_armhf.deb 8bcb332fe628f8ab933a3da56dd297fa450baefdd9cdb17b2c7849bdf15cc9ef 98708 libnginx-mod-http-perl-dbgsym_1.22.1-9+deb12u6_armhf.deb 2738360b98f5cc8b9cbf2f403a13df5395800fdd0463326fd468a731a1002d34 94712 libnginx-mod-http-perl_1.22.1-9+deb12u6_armhf.deb f115ae9ef669cdaad9dfc6497149d3e180536810a1bd6d0237a06a30d14e8b10 53132 libnginx-mod-http-xslt-filter-dbgsym_1.22.1-9+deb12u6_armhf.deb d89e154ea09aca4f87d03670b17fd0e936b52aa451dea2d6497d6931d9287c37 86344 libnginx-mod-http-xslt-filter_1.22.1-9+deb12u6_armhf.deb d1736c599c7bea04df15726c2cc47e54cd8c81eeb8a2d20869d6bdb11df3fa7b 110096 libnginx-mod-mail-dbgsym_1.22.1-9+deb12u6_armhf.deb 17d22955934fce46d873f20fe342179930356430817db289f122073b60b54666 114952 libnginx-mod-mail_1.22.1-9+deb12u6_armhf.deb a06f57532c8c60c99e41a3ab5bcebf7b573827856764b8c6742816e760b01601 175404 libnginx-mod-stream-dbgsym_1.22.1-9+deb12u6_armhf.deb f3ce2dd3a7e507d8069861b0660def234207d5f502724fe3ff417ce020210867 22712 libnginx-mod-stream-geoip-dbgsym_1.22.1-9+deb12u6_armhf.deb e17e0e812058e63cf2f6c75eb94500d1ad6c774fa6fd223b941cf702208387ac 83864 libnginx-mod-stream-geoip_1.22.1-9+deb12u6_armhf.deb dfdaf3b25029ce38e177f1ae282131031bc75262c3b27a3504b9f1901d433bc6 134872 libnginx-mod-stream_1.22.1-9+deb12u6_armhf.deb 897eda68db5160aa8223dd66c0d17e9724a5da784a455498b37b7a9daca78860 1117740 nginx-dbgsym_1.22.1-9+deb12u6_armhf.deb ca88de8ecdd0791c59067c5ffd9efaf111809781c03617543e49008aed13334d 80812 nginx-extras_1.22.1-9+deb12u6_armhf.deb 6e0af0f2088a9edada3cc416636e4ee5bebedf65437ac431c5f087084986a0c9 14091 nginx_1.22.1-9+deb12u6_armhf-buildd.buildinfo 63b3266c96836892f089fddecd6c13f5f585eb0b6076ef6d94acd8089c223cdc 472400 nginx_1.22.1-9+deb12u6_armhf.deb Files: 5cfc9e39762d87d251f218cbce0a396a 36888 debug optional libnginx-mod-http-geoip-dbgsym_1.22.1-9+deb12u6_armhf.deb 399c0534e91e4ecb19b0ccb5f5639787 84504 httpd optional libnginx-mod-http-geoip_1.22.1-9+deb12u6_armhf.deb 53523304dfa59315338e01f1415ec9f4 44280 debug optional libnginx-mod-http-image-filter-dbgsym_1.22.1-9+deb12u6_armhf.deb 50e1aafd261be2f72005c328a16e271f 87912 httpd optional libnginx-mod-http-image-filter_1.22.1-9+deb12u6_armhf.deb 6bdafdc4540f6bcde66d217cd56c2765 98708 debug optional libnginx-mod-http-perl-dbgsym_1.22.1-9+deb12u6_armhf.deb 2f4e2d3f4b9c9b6ae46dc6a3d9285abc 94712 httpd optional libnginx-mod-http-perl_1.22.1-9+deb12u6_armhf.deb 403dfa55538d13ef790a0e7c1321d389 53132 debug optional libnginx-mod-http-xslt-filter-dbgsym_1.22.1-9+deb12u6_armhf.deb 8f6609b3ab36e527c67d6f4fb0645345 86344 httpd optional libnginx-mod-http-xslt-filter_1.22.1-9+deb12u6_armhf.deb d6106e7fc52ad317c6cc693af1fdecc3 110096 debug optional libnginx-mod-mail-dbgsym_1.22.1-9+deb12u6_armhf.deb c3ddb1619f497c4c1bc991478368197d 114952 httpd optional libnginx-mod-mail_1.22.1-9+deb12u6_armhf.deb 8e5c162ed4e2fc104fabc0fc92b9ea89 175404 debug optional libnginx-mod-stream-dbgsym_1.22.1-9+deb12u6_armhf.deb 05ef81c65471503d979f6b382364b993 22712 debug optional libnginx-mod-stream-geoip-dbgsym_1.22.1-9+deb12u6_armhf.deb 9707a95b97344e893b20decf6683722c 83864 httpd optional libnginx-mod-stream-geoip_1.22.1-9+deb12u6_armhf.deb 1e4e4be09bfcbc31a69157ca3eea4ce9 134872 httpd optional libnginx-mod-stream_1.22.1-9+deb12u6_armhf.deb 0f11affd751ba47a49d2480cfefeec4a 1117740 debug optional nginx-dbgsym_1.22.1-9+deb12u6_armhf.deb 9c6f11ee1ac4d59db507564b4d8964e5 80812 httpd optional nginx-extras_1.22.1-9+deb12u6_armhf.deb 77429ce3d7829b0d4479cf134ac38dab 14091 httpd optional nginx_1.22.1-9+deb12u6_armhf-buildd.buildinfo c28185e2165467b31bab27666c6dfa2c 472400 httpd optional nginx_1.22.1-9+deb12u6_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmn5g10ACgkQnwznazfj XTpYhw//cfjXB6HPk/Oj4NxRBEyWY/5CiMIqaDN9M25apEDDqWfN5A/aEpRU8SZV vwhjn/boFVvSZStvkYc2qWIPaFARbrVtK3nN2XsqPnlXA6RdmA+BnTVtVgqRRfWt AQz26wCY3GBcqpGJGnY/XyOPFFrPtcLECpxxoV9mIwshwLrUBOcGzCowO8mH5+zU oqYq5hR4MOFOTO1nM4O8rudTgzXJM9qBWFmUdLwEBs38JhZmypO2TQAOz866M4D8 tl55oR4UN0DsMrjmYA6a0oA9tbWR18lWWwl8paQ+jLWd4b7QpNhM8YVidr+m7Un2 B1oeQAE+ZOeOtLyLN2PbtBhIYvECdZpSotuPkZDtE3rU/uUWvu8QAFNFAH7ye2Be 5tIXWU56ru6MRCmUbjvsYvS1uYknGQEMYRv+E+tn0TmRkqiDOTW9C6fpuTcNbhDt 0h+VX1ix8Oq2UxJViMvjsAfMWmQXqhV4Y2R3ptSp0I90IT7iQ68OKetd0fWwaj4M 4zhz56y3J4FwDO+btbgBK9AE0mFdUpp/MHUBPz8YGLf7BPo89UbSDwi4VHYmX1Ap Z1VwgOexGNYQfMC9NaZMyDAYuGI0vh9Rz8mlanmSfCRhyMOHSJvo5EqTpvSeSnbK oOCOVhtTtVBxvSpQYddQlkZ4LJl+W4XGM2MwWBdMH2Mon/Muzps= =mScF -----END PGP SIGNATURE-----