.. _version_history_1.38.5: 1.38.5 (October 1, 2026) ========================= Bug fixes --------- *Changes expected to improve the state of the world and are unlikely to have negative effects* * **tls**: Fix: `CVE-2026-35189 `_ Patched BoringSSL to fix excessive memory allocation when parsing X.509 certificates containing CRL Distribution Points with ``nameRelativeToCRLIssuer`` entries. A single specially crafted certificate under the normal per-certificate size limit could trigger hundreds of MiB of heap allocation, allowing a remote denial of service via TLS handshakes. The unused ``nameRelativeToCRLIssuer`` processing has been removed. The BoringSSL FIPS build (``--config=boringssl-fips``) does not receive this patch. Removed config or runtime ------------------------- *Normally occurs at the end of the* :ref:`deprecation period ` * **build**: Removed Debian bullseye (11) packaging. Debian bullseye is end-of-life (LTS ended 31 August 2026) and its package repositories are no longer available on the main Debian mirrors. Bullseye ``.deb`` packages are no longer built or published.