From: Blackeye <14815724-Blackstareye@users.noreply.gitlab.com> Date: Thu, 28 May 2026 18:21:13 +0000 (+0200) Subject: Merge branch 'proposal_ci_php_linting_with_warning' into 'next-release' X-Git-Tag: 4.7.2~11 X-Git-Url: https://git.p6c8.net/jirafeau/jirafeau.git/commitdiff_plain/146ce80b73e7c0e8533d445e8464862a44117295?hp=4d40183a0cded8d2588628cf427313858c0057bb Merge branch 'proposal_ci_php_linting_with_warning' into 'next-release' Proposal ci php linting with warning See merge request jirafeau/Jirafeau!32 --- diff --git a/CHANGELOG.md b/CHANGELOG.md index ed7b741..5e614ec 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,7 +19,7 @@ ## Version 4.7.1 -- Fixed another possibility to bypass the checks for [CVE-2022-30110](https://www.cve.org/CVERecord?id=CVE-2022-30110), [CVE-2024-12326](https://www.cve.org/CVERecord?id=CVE-2024-12326) and [CVE-2025-7066](https://www.cve.org/CVERecord?id=CVE-2025-7066) (prevent preview of SVG images and other critical files) by sending a manipulated HTTP request with a MIME type like "image". When doing the preview, the browser tries to automatically detect the MIME type resulting in detecting SVG and possibly executing JavaScript code. To prevent this, MIME sniffing is disabled. +- Fixed another possibility to bypass the checks for [CVE-2022-30110](https://www.cve.org/CVERecord?id=CVE-2022-30110), [CVE-2024-12326](https://www.cve.org/CVERecord?id=CVE-2024-12326) and [CVE-2025-7066](https://www.cve.org/CVERecord?id=CVE-2025-7066) (prevent preview of SVG images and other critical files) by sending a manipulated HTTP request with a MIME type like "image". When doing the preview, the browser tries to automatically detect the MIME type resulting in detecting SVG and possibly executing JavaScript code. To prevent this, MIME sniffing is disabled. This issue has subsequently been reported as [CVE-2026-1466](https://www.cve.org/CVERecord?id=CVE-2026-1466). - The default value of `max_upload_chunk_size_bytes` was set to `5000000`. Higher values could trigger a bug Chromium-based browsers on servers with HTTP/3 enabled, causing asynchronous uploads to fail. - Docker image: Updated PHP to 8.3 and removed `mime-types.conf` from `lighttpd.conf` - Upgrade from 4.7.0: in-place upgrade, you also should set `max_upload_chunk_size_bytes` to `5000000` in your `config.local.php`!