-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 13 Oct 2025 14:09:20 +0200 Source: mitmproxy Built-For-Profiles: noudeb Architecture: source Version: 8.1.1-4 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Gianfranco Costamagna <locutusofborg@debian.org> Closes: 1071640 1103701 1110243 Changes: mitmproxy (8.1.1-4) unstable; urgency=medium . [ Emmanuel Arias ] * Team upload. * d/patches/0008-Stop-using-blinker._saferef.patch: Add patch to stop using blinker._saferef module (Closes: #1071640, #1110243). * Fix CVE-2025-23217: mitmweb's API now requires an authentication token by default. While the client cannot access the API directly, they can access the API through the proxy. An attacker may be able to escalate this SSRF-style access to remote code execution (Closes: #1103701). Checksums-Sha1: 6615b934ddd7762fd1884bf6d576025c948db999 2974 mitmproxy_8.1.1-4.dsc 6bd081352ea4b784e3fdcd019e23e86ee3b3aa0a 15776 mitmproxy_8.1.1-4.debian.tar.xz fc676697d406366da06140e150218a372714b80b 8084 mitmproxy_8.1.1-4_source.buildinfo Checksums-Sha256: 3ce0cafe373eb01379d7d643a46786c73fbc142c044579d45725ce576a189cdc 2974 mitmproxy_8.1.1-4.dsc b382a7a42e9bf0fddae1b9861c17562ac488d49804385165b8fdff607ae85b46 15776 mitmproxy_8.1.1-4.debian.tar.xz 2c7cf559019182483adf7cde8c398c2146f42ed6f6fc3653bc7cc199d4927601 8084 mitmproxy_8.1.1-4_source.buildinfo Files: 0755cf106d2a86f8b4b850f7ef3c080d 2974 net optional mitmproxy_8.1.1-4.dsc 8ffdf249c4aaf2d3f159f3a96da46eb5 15776 net optional mitmproxy_8.1.1-4.debian.tar.xz 40c72df30c1e5a4dc2530f3055f8a494 8084 net optional mitmproxy_8.1.1-4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEkpeKbhleSSGCX3/w808JdE6fXdkFAmjs8HcACgkQ808JdE6f XdmSjg//d4XiVXdp3gr+AasLu0GmCnyusWftgwLuPcZoyM8mpgWRd0ej30PJSgxq 28MYmwlfStz2SeGl8tSx9NEgnz1de+9WYtc3WFnrjXGYfgJLiz3CKrDnG6K0CTkQ I4tyWNfWMceHQyAz0ytmUdkQx5t4c02kBY/ysUvZ4SRv0HgDGSeYI9RMGoixSYZq N1t/YypMqKdtfAZCPRL8UcBCnIG7kczPjiOxB1s6HjJcVaVJaYCESeMsZsTF09xD jWYZbqvWoo7FE/ZLzV8LEEopm8twxer+o7ygmSAAWR4VoqoPoZ2UGX4bCmh4vP1a rQCM6OCo1JpM+6NFaAe7L9XlVW8f06x8JYj+3ivPlTF2psZTCYrh+JFl0Ogr+2Nx Eh/o9QMqob5tAjJZPyxWdeX7Xn7JEDFLULBddq2F0D6FA5OxnAnAH5xVpB7DgY+7 SW9WZIRO/eR9LBaASU/dzXio4IvT9SE8GJI/t4mGhvDNO2qigNJ7RnC5RbX8H/yH r3uWJZdGzZLvLQNwC5Q+NGnOMvNVqa40xD3v4HjaJIRwXNevhHLV1dFRbv/W5GBf 70c3Hwd6GNtYQodrEgs5U3chMwAAZTe3IE3bw5+lHuMfvERJwpRceFdiTWhkiZ7w OkbOY3t1CfvQ8JdCFnzsrahNrhaKyExvBvmewCSL2VovhIj7czQ= =Im32 -----END PGP SIGNATURE-----