1.36.11 (October 1, 2026)
Bug fixes
Changes expected to improve the state of the world and are unlikely to have negative effects
tls: Fix: CVE-2026-35189
Patched BoringSSL to fix excessive memory allocation when parsing X.509 certificates containing CRL Distribution Points with
nameRelativeToCRLIssuerentries. A single specially crafted certificate under the normal per-certificate size limit could trigger hundreds of MiB of heap allocation, allowing a remote denial of service via TLS handshakes. The unusednameRelativeToCRLIssuerprocessing has been removed. Note that the FIPS build (--define boringssl=fips) is not patched.
Removed config or runtime
Normally occurs at the end of the deprecation period
build: Removed Debian bullseye (11) packaging. Debian bullseye is end-of-life (LTS ended 31 August 2026) and its package repositories are no longer available on the main Debian mirrors. Bullseye
.debpackages are no longer built or published.