From 201936805e4819f639f0e20352d7b94f51786f56de91fe54c71404d3ed505669 Mon Sep 17 00:00:00 2001 From: Robert Frohl Date: Tue, 20 Jan 2026 15:33:11 +0100 Subject: [PATCH] Update submodules from pool/python-weasyprint#1 and create patchinfo.20260120143234408409.93181000773252/_patchinfo --- .../_patchinfo | 15 +++++++++++++++ python-weasyprint | 2 +- 2 files changed, 16 insertions(+), 1 deletion(-) create mode 100644 patchinfo.20260120143234408409.93181000773252/_patchinfo diff --git a/patchinfo.20260120143234408409.93181000773252/_patchinfo b/patchinfo.20260120143234408409.93181000773252/_patchinfo new file mode 100644 index 0000000..7798d5b --- /dev/null +++ b/patchinfo.20260120143234408409.93181000773252/_patchinfo @@ -0,0 +1,15 @@ + + VUL-0: CVE-2025-68616: python-weasyprint: server-side request forgery (SSRF) protection bypass via HTTP redirects allows access to internal network resources + VUL-0: CVE-2025-68616: python-weasyprint: server-side request forgery (SSRF) protection bypass via HTTP redirects allows access to internal network resources + dgarcia + important + security + Security update for python-weasyprint + This update for python-weasyprint fixes the following issues: + +Changes in python-weasyprint: + +- CVE-2025-68616: Fixed a server-side request forgery in default fetcher (boo#1256936). + + python-weasyprint + diff --git a/python-weasyprint b/python-weasyprint index 7179e10..6a88841 160000 --- a/python-weasyprint +++ b/python-weasyprint @@ -1 +1 @@ -Subproject commit 7179e10f1f24e3a3b8bdd27ab101c4a736fc9c2aba535332c7267d36d846def2 +Subproject commit 6a88841ded139db1c5e76df4f84f8aa9ea76b9c43e6748e0ecb60c2036e379ba -- 2.51.1