Control: tags -1 + moreinfo

On Sun, 2026-02-22 at 17:10 +0900, yokota wrote:
> I was updated my debdiff patch to fix more CVEs.
> * CVE-2026-26064: Path Traversal
> * CVE-2026-26065: Path Traversal

+  * CVE-2026-25731: ZIP Output: Change the template engine used for HTML
+    templating from templite to Mustache, for greater safety and
+    performance. Note that this is a breaking change if you use custom
+    templates with ZIP output.

Do we have any idea how likely it is that users will be affected here?
Is it worth a NEWS file?

regards,

Adam

Reply via email to