.. _version_history_1.36.11: 1.36.11 (October 1, 2026) ========================== Bug fixes --------- *Changes expected to improve the state of the world and are unlikely to have negative effects* * **tls**: Fix: `CVE-2026-35189 `_ Patched BoringSSL to fix excessive memory allocation when parsing X.509 certificates containing CRL Distribution Points with ``nameRelativeToCRLIssuer`` entries. A single specially crafted certificate under the normal per-certificate size limit could trigger hundreds of MiB of heap allocation, allowing a remote denial of service via TLS handshakes. The unused ``nameRelativeToCRLIssuer`` processing has been removed. Note that the FIPS build (``--define boringssl=fips``) is not patched. Removed config or runtime ------------------------- *Normally occurs at the end of the* :ref:`deprecation period ` * **build**: Removed Debian bullseye (11) packaging. Debian bullseye is end-of-life (LTS ended 31 August 2026) and its package repositories are no longer available on the main Debian mirrors. Bullseye ``.deb`` packages are no longer built or published.