Index | Thread | Search

From:
izzy Meyer <izder456@disroot.org>
Subject:
lang/crystal should be updated to at least 1.19.2 to patch builtin HTTP server vuln
To:
ports@openbsd.org
Cc:
jcs@jcs.org
Date:
Thu, 18 Jun 2026 13:17:47 -0500

Download raw body.

Thread
  • izzy Meyer:

    lang/crystal should be updated to at least 1.19.2 to patch builtin HTTP server vuln

Hello ports@ (CC'd maintainer too)

What subject line says. Ideally it should be updated to the latest if
possible though. 

More info here [1]

I would have submitted a diff to update this myself, but this port
depends on a tarball distfile used in the bootstrap process from jcs's
domain, so I can't do that easily.

Thanks. I'm a heavy user of the crystal language on OpenBSD so having an
update to fix this security issue would be appreciated.

[1]
https://crystal-lang.org/2026/05/26/http-request-smuggling-vulnerability-in-http-server/

-- 
iz (she/her)

> I say mundane things
> so the uninteresting
> just might get noticed.

izder456 (dot) neocities (dot) org