Opened 2 months ago
Closed 2 months ago
#23612 closed enhancement (fixed)
HTTP-Date-6.08
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point release. Fixes CVE-2026-14741.
Change History (2)
comment:1 by , 2 months ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
comment:2 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-154 has been issued.
Note:
See TracTickets
for help on using tickets.

6.08 2026-07-09 02:04:21Z - [SECURITY] Reject input longer than 64 characters in parse_date() to prevent quadratic regex backtracking (a denial of service) on hostile date strings. Fixes CVE-2026-14741. (Olaf Alders) 6.07 2026-06-25 15:12:09Z - Add test with Time::Zone (GH#25) (Michal Josef Špaček) - Add test with bad Time::Zone string (GH#26) (Michal Josef Špaček) - Add tests with negative time (GH#26) (Michal Josef Špaček) - Replace all instances of \d with [0-9] in regular expressions to reject non-ASCII Unicode digits, with a regression test (GH#27) (Robert Rothenberg) - Reject malformed ISO 8601 timezones with a doubled colon (GH#31) (Olaf Alders) - Document day/month/year ordering for numeric dates (GH#32) (Olaf Alders)Fixed at c18cf7423e. Leaving open for SA.