From nobody Sun Apr 5 11:56:07 2026 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fpWBc5DYLz6Z1FR for ; Sun, 05 Apr 2026 11:56:08 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fpWBb4nmjz3HnR for ; Sun, 05 Apr 2026 11:56:07 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1775390167; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WgIY+bR7A5qucsf0eO4TLPJRFEFo2Y/I6hGPwUk4ojg=; b=dYlarXEeX5fl674tlXh4VS3FDcLuQ8UPYutvOu5OiYUfm8/d0jCgKKzDqE89MGAojpMpaY GoDuABqAvDq0VQsNFjmN8hJtJWljkidYNwjSJI/agZDrsVaSfdaxqVOIaMZ54s7fyxnyLH FvLNFGLPjSyfPJIQC7JdtGy2abK5Dm/stw/DYPGGnG6pIzzlwVMeLn74Kih4WxGGxxRbY7 pB7eC0Ywnf3MnUG8Cj0luOYTPf1hMzwNJ+V/8pZLjP9bO5GPr5ynrz4VVXIWRAbl9lCj4N 38vRd1qgEZ+ongjSvL4UbQr7kUxLvFdmVqqevKLkp6V6luWrB0J9OLaevOqUzA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1775390167; a=rsa-sha256; cv=none; b=VCD6UeD0JHQgU6Y7Br73NxafcOyzBTThnQAA7w/AFXJvn46zKytzxgRinOyNNdq5FXTH/o FHxNiKIHt4hy8HMvs273Phx33wzV8kOK7ib9qk9dzDQO7KDXSRMzlM/U/SQUe33dtR2OtX lFmgm6N+6cc4hdWizFo4S3AIRAraQjWHXV/gT3aLd3E014HT+LKqpv2aC65CMqw80chRuM rTyk213y0AVbLGFoYmV8H0GhgC/bYAciQpR+2KdDKSGjQXadSnblvalmTT3omNgGlvk0FB Ves3FclAFbY0eLYhSPsj8bqdnkBzxOB1ClJF4mdOHIKvV1tFBt1hcsR18XLHQw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1775390167; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WgIY+bR7A5qucsf0eO4TLPJRFEFo2Y/I6hGPwUk4ojg=; b=sfvr0VDmdnRYrmJaRQRnC1uWAyutdHG55MtbuVCBp5rqdnXVCrROcLzo9BQYgbDkH80t5k foRyGSZzKI+a3gcrt4Cxkv9IvykCpNxMhlTM9FveO2ABXnryS3sQlLWn398WTaSY8yXK/C DNylr34dWVNb6JnxfP0U7QZS7xHHf/heFHTHpothlJPjFz4S3pcqPT1Nsu/2PNsKLX2rQ5 56Jr3ssFNOxIgkPT7ej/2Wy4NaSTk6ZEhK27+EKsKms8gwtwFw/uKXEPwxXaANR38SZPbG MJqxAapxOcsenHgTAfBZF8QUNpnAEKg5cs6Twx+Yh0w4qAr3KF8ZQlFbs1UCVQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4fpWBb3rglz13x4 for ; Sun, 05 Apr 2026 11:56:07 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 22da5 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sun, 05 Apr 2026 11:56:07 +0000 To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Fernando Apeste=?utf-8?Q?gu=C3=ADa?= Subject: git: f2b8dcc5bc95 - main - security/vuxml: Add {lib}nghttp2 vulneability List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: f2b8dcc5bc953e4ae50853ea2eab0d812d7f8fb7 Auto-Submitted: auto-generated Date: Sun, 05 Apr 2026 11:56:07 +0000 Message-Id: <69d24dd7.22da5.69f9442c@gitrepo.freebsd.org> The branch main has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=f2b8dcc5bc953e4ae50853ea2eab0d812d7f8fb7 commit f2b8dcc5bc953e4ae50853ea2eab0d812d7f8fb7 Author: Fernando ApesteguĂ­a AuthorDate: 2026-04-05 11:54:26 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2026-04-05 11:54:26 +0000 security/vuxml: Add {lib}nghttp2 vulneability CVE-2026-27135 Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H --- security/vuxml/vuln/2026.xml | 45 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml index 3fd0c9e165e1..a538ae1d46ed 100644 --- a/security/vuxml/vuln/2026.xml +++ b/security/vuxml/vuln/2026.xml @@ -1,3 +1,48 @@ + + nghttp2 -- CWE-617: Reachable Assertion + + + libnghttp2 + 1.68.1 + + + nghttp2 + 1.68.1 + + + + +

https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 reports:

+
+

+ nghttp2 is an implementation of the Hypertext Transfer + Protocol version 2 in C. Prior to version 1.68.1, the + nghttp2 library stops reading the incoming data when user + facing public API `nghttp2_session_terminate_session` or + `nghttp2_session_terminate_session2` is called by the + application. They might be called internally by the + library when it detects the situation that is subject to + connection error. Due to the missing internal state + validation, the library keeps reading the rest of the data + after one of those APIs is called. Then receiving a + malformed frame that causes FRAME_SIZE_ERROR causes + assertion failure. nghttp2 v1.68.1 adds missing state + validation to avoid assertion failure. No known + workarounds are available. +

+
+ +
+ + CVE-2026-27135 + https://cveawg.mitre.org/api/cve/CVE-2026-27135 + + + 2026-03-18 + 2026-04-05 + +
+ MongoDB Server -- CWE-617: Reachable Assertion