1.36.11 (October 1, 2026)

Bug fixes

Changes expected to improve the state of the world and are unlikely to have negative effects

  • tls: Fix: CVE-2026-35189

    Patched BoringSSL to fix excessive memory allocation when parsing X.509 certificates containing CRL Distribution Points with nameRelativeToCRLIssuer entries. A single specially crafted certificate under the normal per-certificate size limit could trigger hundreds of MiB of heap allocation, allowing a remote denial of service via TLS handshakes. The unused nameRelativeToCRLIssuer processing has been removed. Note that the FIPS build (--define boringssl=fips) is not patched.

Removed config or runtime

Normally occurs at the end of the deprecation period

  • build: Removed Debian bullseye (11) packaging. Debian bullseye is end-of-life (LTS ended 31 August 2026) and its package repositories are no longer available on the main Debian mirrors. Bullseye .deb packages are no longer built or published.