Control: tags -1 + moreinfo On Sun, 2026-02-22 at 17:10 +0900, yokota wrote: > I was updated my debdiff patch to fix more CVEs. > * CVE-2026-26064: Path Traversal > * CVE-2026-26065: Path Traversal
+ * CVE-2026-25731: ZIP Output: Change the template engine used for HTML + templating from templite to Mustache, for greater safety and + performance. Note that this is a breaking change if you use custom + templates with ZIP output. Do we have any idea how likely it is that users will be affected here? Is it worth a NEWS file? regards, Adam

