-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 22 Apr 2026 20:15:43 +0000 Source: nginx Binary: libnginx-mod-http-geoip libnginx-mod-http-geoip-dbgsym libnginx-mod-http-image-filter libnginx-mod-http-image-filter-dbgsym libnginx-mod-http-perl libnginx-mod-http-perl-dbgsym libnginx-mod-http-xslt-filter libnginx-mod-http-xslt-filter-dbgsym libnginx-mod-mail libnginx-mod-mail-dbgsym libnginx-mod-stream libnginx-mod-stream-dbgsym libnginx-mod-stream-geoip libnginx-mod-stream-geoip-dbgsym nginx nginx-dbgsym nginx-extras Architecture: i386 Version: 1.22.1-9+deb12u6 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Jan Mojžíš Description: libnginx-mod-http-geoip - GeoIP HTTP module for Nginx libnginx-mod-http-image-filter - HTTP image filter module for Nginx libnginx-mod-http-perl - Perl module for Nginx libnginx-mod-http-xslt-filter - XSLT Transformation module for Nginx libnginx-mod-mail - Mail module for Nginx libnginx-mod-stream - Stream module for Nginx libnginx-mod-stream-geoip - GeoIP Stream module for Nginx nginx - small, powerful, scalable web/proxy server nginx-extras - nginx web/proxy server (extended version) Changes: nginx (1.22.1-9+deb12u6) bookworm; urgency=medium . * d/conf/*_params: use "$host" instead of "$http_host" * "$http_host" forwards the Host header exactly as supplied by the client and may not match the effective request target (e.g. absolute-form requests with a conflicting Host header) this can expose inconsistent or attacker-controlled host values to backend applications (uwsgi, fastcgi, scgi, proxy) * switch to "$host" as a safer, normalized alternative * note: this changes behaviour, as "$host" does not preserve the client-supplied port; deployments relying on "$http_host" including a port number may be affected * it is workaround for Debian bug #1126960 for stable/oldstable release Checksums-Sha1: 4d5a8e33aa2e49c1f59bc004485a29fcb986da5e 35772 libnginx-mod-http-geoip-dbgsym_1.22.1-9+deb12u6_i386.deb faa569761d50eecda2716f349735495664101fc9 85712 libnginx-mod-http-geoip_1.22.1-9+deb12u6_i386.deb c223d1cdf7e9cdc5991b483125f63814eb8492dc 42956 libnginx-mod-http-image-filter-dbgsym_1.22.1-9+deb12u6_i386.deb 8b3458ec4d2208dbd1179ac1fdc689a8a3455254 89328 libnginx-mod-http-image-filter_1.22.1-9+deb12u6_i386.deb 1822a23c716e2da0aa954ae6864f1b945f521b8d 94724 libnginx-mod-http-perl-dbgsym_1.22.1-9+deb12u6_i386.deb 66c7d95ec39ae18460b5d22d2aad5365e4ef52c6 98704 libnginx-mod-http-perl_1.22.1-9+deb12u6_i386.deb 54f5eb8ea186b2b1f561f6ec621570034771482b 51820 libnginx-mod-http-xslt-filter-dbgsym_1.22.1-9+deb12u6_i386.deb 6a6192fea1e5963574f6a968c14bf40b82a8b0f3 87928 libnginx-mod-http-xslt-filter_1.22.1-9+deb12u6_i386.deb 44e43419124d91c6c0cc2db2ebe9c07575d9cb11 102308 libnginx-mod-mail-dbgsym_1.22.1-9+deb12u6_i386.deb 5b084d7f779ac950af59d2cba5cd493845a7f816 122256 libnginx-mod-mail_1.22.1-9+deb12u6_i386.deb 5b3f3c0505da6b7918c4abc949b87d86733fad7b 159980 libnginx-mod-stream-dbgsym_1.22.1-9+deb12u6_i386.deb 6c93afe52e0a9642918cac2d24817d7ccbdda4c9 21852 libnginx-mod-stream-geoip-dbgsym_1.22.1-9+deb12u6_i386.deb 22200296356551b205ce7208aca23e0be6fbbfc0 84824 libnginx-mod-stream-geoip_1.22.1-9+deb12u6_i386.deb 5b052a526e223a8da766305346d0683347ada887 150620 libnginx-mod-stream_1.22.1-9+deb12u6_i386.deb 4c998de6c731b2fb5e8e3ac6b9a28b55d629b510 1018832 nginx-dbgsym_1.22.1-9+deb12u6_i386.deb d4d1d4d864957d1036d181fc29d2374fcc7957be 80808 nginx-extras_1.22.1-9+deb12u6_i386.deb 61290eeae3584fc8befcced5fd56e3b4b0bc456e 14102 nginx_1.22.1-9+deb12u6_i386-buildd.buildinfo 586ff118b58ee7025a4a405b1ecff137b7cefd4e 571628 nginx_1.22.1-9+deb12u6_i386.deb Checksums-Sha256: ea78e33e69ed0dff2a9f0c5f845db2aa4b5342a561ca1a668b81be5533e4c6f7 35772 libnginx-mod-http-geoip-dbgsym_1.22.1-9+deb12u6_i386.deb 78d08d7dbdc37e270a55e2136b25b3172cbb87c55312caeccd4947f6485376d3 85712 libnginx-mod-http-geoip_1.22.1-9+deb12u6_i386.deb 7e177e4b665224d6532aca17afcd9ed23eb7f917f8a0a3b42ae120058771c2d6 42956 libnginx-mod-http-image-filter-dbgsym_1.22.1-9+deb12u6_i386.deb 312006349c69001fbdb2b09ebe9773e4ff5f335d5abd6506ecca8566a2299c40 89328 libnginx-mod-http-image-filter_1.22.1-9+deb12u6_i386.deb a53fc057100f84b2641ca18f882ca9601c62ffddb229de54b24c968c0982ae8d 94724 libnginx-mod-http-perl-dbgsym_1.22.1-9+deb12u6_i386.deb 3cd8cc000bb6987ef3482f3bd0abfaeebb947ed98a03f1fe0451bee76d429371 98704 libnginx-mod-http-perl_1.22.1-9+deb12u6_i386.deb 928cabc5d38c2b009b292b8a30c80afeb535ad1633a26dcf3cdc19804339ebbf 51820 libnginx-mod-http-xslt-filter-dbgsym_1.22.1-9+deb12u6_i386.deb bbe0b64c01ee3f9455992ad57443468cdb27a1e516b43752e99e35e5db423b00 87928 libnginx-mod-http-xslt-filter_1.22.1-9+deb12u6_i386.deb fb47eab4adad44cb3d5443f76a7d76a982fc46a57b93be2151e51964fe50a983 102308 libnginx-mod-mail-dbgsym_1.22.1-9+deb12u6_i386.deb 76531a763569ae007003a051ced74bff91325ad49b4a41927cae47ae99a8fe09 122256 libnginx-mod-mail_1.22.1-9+deb12u6_i386.deb 718c3c6385b23e8ff22a52a3dd6bfafdbe3a48ed71e27e9884c2772716b2e501 159980 libnginx-mod-stream-dbgsym_1.22.1-9+deb12u6_i386.deb 6f3d2127c6ea498167aef6caa405e9f4a7e29ed927410af9898b7b434e77eeff 21852 libnginx-mod-stream-geoip-dbgsym_1.22.1-9+deb12u6_i386.deb d67e0363fcfddc822cb4d1b5e5e66cbfbfcf71cf2965f41b94e92aac7d4e228f 84824 libnginx-mod-stream-geoip_1.22.1-9+deb12u6_i386.deb e2684e5d4366c45798078024d40ff9b301c371399633e4f0006bcab5458e6ce9 150620 libnginx-mod-stream_1.22.1-9+deb12u6_i386.deb 315baa1e0cec08db5ffe123941c52c53192db0e721749c4825380b563bd25a51 1018832 nginx-dbgsym_1.22.1-9+deb12u6_i386.deb 0d9e0681ec08581a37c011d170af60585ed86d0c2dc8bebe1a9559ceeddc41d4 80808 nginx-extras_1.22.1-9+deb12u6_i386.deb 234eaa371a0451de88cc8ae046f7e08587f1d794bf772f3550b5ae09c0645b20 14102 nginx_1.22.1-9+deb12u6_i386-buildd.buildinfo bea916137fa945a3a8443d83e96ce7b92582f41474db6bfe8d9d0e49177f9638 571628 nginx_1.22.1-9+deb12u6_i386.deb Files: ed19a186fe9fd6f6a1f08f616a2678a7 35772 debug optional libnginx-mod-http-geoip-dbgsym_1.22.1-9+deb12u6_i386.deb 36a8726d6c94dfffffe4c93d6045ed9a 85712 httpd optional libnginx-mod-http-geoip_1.22.1-9+deb12u6_i386.deb a3fc9b060b444e1e2238fd1ee308f21e 42956 debug optional libnginx-mod-http-image-filter-dbgsym_1.22.1-9+deb12u6_i386.deb 2649f1cc95873f43f54cce7f8a37d5a8 89328 httpd optional libnginx-mod-http-image-filter_1.22.1-9+deb12u6_i386.deb 27e2e68d12fd3fc628a4e3fe5f3cd36e 94724 debug optional libnginx-mod-http-perl-dbgsym_1.22.1-9+deb12u6_i386.deb fd652e3ec6d2b0031702026531273539 98704 httpd optional libnginx-mod-http-perl_1.22.1-9+deb12u6_i386.deb e1a825d89bdc63c8b6700676d232a28f 51820 debug optional libnginx-mod-http-xslt-filter-dbgsym_1.22.1-9+deb12u6_i386.deb d63274d303527d86bc629a3fa29e2bdb 87928 httpd optional libnginx-mod-http-xslt-filter_1.22.1-9+deb12u6_i386.deb d92fe654a07f8000d91eac6b10152d46 102308 debug optional libnginx-mod-mail-dbgsym_1.22.1-9+deb12u6_i386.deb 2acf4b9287dd48c25be757f4a09838a0 122256 httpd optional libnginx-mod-mail_1.22.1-9+deb12u6_i386.deb ffd421c415f176061b6d36ca3f60814f 159980 debug optional libnginx-mod-stream-dbgsym_1.22.1-9+deb12u6_i386.deb c845ed033e4d38d9070f84d41a12e314 21852 debug optional libnginx-mod-stream-geoip-dbgsym_1.22.1-9+deb12u6_i386.deb dcb1a5e5e06a049efd3c1b4276ca228f 84824 httpd optional libnginx-mod-stream-geoip_1.22.1-9+deb12u6_i386.deb a473902880c3cf2363784b124429e8d4 150620 httpd optional libnginx-mod-stream_1.22.1-9+deb12u6_i386.deb f81e37b65a3531e8fb7edf34250ade07 1018832 debug optional nginx-dbgsym_1.22.1-9+deb12u6_i386.deb 2bd4d2fd42d8d0e453f503340f96486a 80808 httpd optional nginx-extras_1.22.1-9+deb12u6_i386.deb f612d9ab14cf04a56de91367efdeccf5 14102 httpd optional nginx_1.22.1-9+deb12u6_i386-buildd.buildinfo 474ddcf9fea6ade9c2333228918c5320 571628 httpd optional nginx_1.22.1-9+deb12u6_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmn5g1wACgkQTwt/65ON 6zdqgA/+Jrzby0JdaFBH0wIFZUxk/DfMe5pkMnffmMaKxJpYs5fA/8Kso3aA7mTM FL5AF5SKVyjQ2CqNfqGE8HqhYdTP5kpPwPW6ZsyoZ57pDH3cMp1I2RSYWcoAYA7S k8B0V8dOC1FoHU+72Pk6hVhnElJW5vq+XC1q/dS87i3ZoED/3qn774zW93NqnrIX fKonSEyrgSgJd83y/+aPUoS2IzpIP+xd8h9c5AjbmuWWcz17uIAUWYo+1UZ21ydz c8rEjDFBHtgxVvIsqbGyY3o6hB/2pNsEvhHFywi7NhvwsL3wwC+lahBKPgRjjJgv vewYYHkgU3FOeed4ezR8N/zM2xWpCsMnD5CHuyUKxuqI4cqWn7Yf4JqBXNItVcIH CQZkSxAScB0VqePMzlrJ8goV+FhZznZXPf5QtmIFfrIYxOWLGB/sQcpmF0yNb3bn 6c/B51b2Av8KfM2u7tn5QkQDLLTCKkx0rTFZ2YI/rDnO0n7JK+0hvKHZmBBWM8Ec Y3icIubAINYB6IdWTYGY9FqrFU9kDj0Zx5QyPqGxXuSou7doKUZtbOZltmjvI2FP EM7Pcw0Tyy7BpqIR8LrG+4x0epTKUzLbpdAvTBS5axg19vZ55KFr0bgdN2bqkvA2 Qyrs/NdOieD9FtWCS/q08OS6bhXjhZy/wqWfglTKdNjzoajVUKc= =dEsj -----END PGP SIGNATURE-----