Hi,
I have just uploaded Swift. It was fixed in Trixie with this announce:
https://lists.debian.org/debian-security-announce/2026/msg00360.html
but please note that Swift in Bookworm is not affected by
CVE-2026-71191, CVE-2026-71192. Remains CVE-2026-71190 and
CVE-2026-50221 that this upload has fixed:
> swift (2.30.1-0+deb12u2) bookworm-security; urgency=medium
>
> * CVE-2026-50221: Swift proxy-server SSRF via internal update header
> injection: applied upstream patch: Block internal update headers at
> the gatekeeper (Closes: #1140678).
> * CVE-2026-71190 / OSSA-2026-031: proxy denial of service via Accept
> header.
> Applied upstream patch:
> - swob: avoid excessive backtracking in Accept parser
> (Closes: #1142973).
>
> -- Thomas Goirand <[email protected]> Wed, 19 Aug 2026 08:59:52 +0200
(rewrapped to fit this message).
Can someone issue the DLA for me please ?
Cheers,
Thomas Goirand (zigo)
P.S: Should follow: Designate.