FreeBSD/ports 8b69d71security/vuxml/vuln 2026.xml

security/vuxml: Document Nginx vulnerabilities

add entry for www/nginx-devel

Sponsored by:   Netzkommune GmbH
DeltaFile
+35-0security/vuxml/vuln/2026.xml
+35-01 files

FreeBSD/ports 0555670sysutils/osquery Makefile, sysutils/osquery/files extra-osquery_events_CMakeLists.txt

sysutils/osquery: Fix build on FreeBSD < 15

Reported by:    pkg-fallout
DeltaFile
+20-0sysutils/osquery/files/extra-osquery_events_CMakeLists.txt
+6-0sysutils/osquery/Makefile
+26-02 files

FreeBSD/ports c70717cscience/v_sim Makefile pkg-plist

science/v_sim: fix plist

It seems that Python files are not always installed at the same location
depending on the platform.

Since I’m there register missing dependencies with minor improvements.

PR:             295393
Reported by:    D. Engberg
DeltaFile
+7-1science/v_sim/Makefile
+0-4science/v_sim/pkg-plist
+7-52 files

FreeBSD/ports 59f5418www/nginx-acme distinfo Makefile, www/nginx-devel distinfo version.mk

www/nginx-devel: Update to 1.31.0

Changes with nginx 1.31.0                                        13 May
2026

    *) Security: when using the "proxy_set_body" directive, an attacker
       might inject data in the proxied request to an HTTP/2 backend
       (CVE-2026-42926).
       Thanks to Mufeed VH of Winfunc Research.

    *) Security: a heap memory buffer overflow might occur in a worker
       process while handling a specially crafted request by
       ngx_http_rewrite_module, potentially resulting in arbitrary code
       execution (CVE-2026-42945).
       Thanks to Leo Lin.

    *) Security: a heap memory buffer overread might occur in a worker
       process while handling a specially crafted response by
       ngx_http_scgi_module or ngx_http_uwsgi_module, allowing an

    [69 lines not shown]
DeltaFile
+3-3www/nginx-acme/distinfo
+3-3www/nginx-devel/distinfo
+1-1www/nginx-acme/Makefile
+1-1www/nginx-devel/version.mk
+8-84 files

FreeBSD/ports f3a9e01net/netatalk4 distinfo Makefile

net/netatalk4: Update to 4.4.3

See https://github.com/Netatalk/netatalk/releases/tag/netatalk-4-4-3 for
a list of changes in this release.
DeltaFile
+3-3net/netatalk4/distinfo
+1-1net/netatalk4/Makefile
+4-42 files

FreeBSD/ports add339daccessibility/at-spi2-core Makefile distinfo

accessibility/at-spi2-core: update to 2.60.3

PR:             294998
DeltaFile
+7-5accessibility/at-spi2-core/Makefile
+3-3accessibility/at-spi2-core/distinfo
+2-1accessibility/at-spi2-core/pkg-plist
+12-93 files

FreeBSD/ports e6ed48ascience/py-pymatgen-core Makefile distinfo, science/py-pymatgen-core/files patch-pyproject.toml patch-src_pymatgen_core_structure.py

science/py-pymatgen-core: update 2026.4.16 → 2026.5.18
DeltaFile
+10-22science/py-pymatgen-core/Makefile
+16-12science/py-pymatgen-core/files/patch-pyproject.toml
+3-3science/py-pymatgen-core/distinfo
+2-2science/py-pymatgen-core/files/patch-src_pymatgen_core_structure.py
+31-394 files

FreeBSD/ports 27c5b4bmath/py-daqp distinfo Makefile

math/py-daqp: update 0.6.0 → 0.8.7
DeltaFile
+3-3math/py-daqp/distinfo
+1-2math/py-daqp/Makefile
+4-52 files

FreeBSD/ports e21c1dcmath/ignition-math pkg-plist Makefile

math/ignition-math: update 6.16.0 → 9.0.0
DeltaFile
+95-145math/ignition-math/pkg-plist
+4-3math/ignition-math/Makefile
+3-3math/ignition-math/distinfo
+102-1513 files

FreeBSD/ports d570f58devel/ignition-msgs pkg-plist Makefile, devel/ignition-msgs/files patch-protobuf

devel/ignition-msgs: update 3.2.0 → 12.0.0
DeltaFile
+901-465devel/ignition-msgs/pkg-plist
+0-25devel/ignition-msgs/files/patch-protobuf
+12-5devel/ignition-msgs/Makefile
+3-3devel/ignition-msgs/distinfo
+916-4984 files

FreeBSD/ports e011d3ddevel Makefile, devel/ignition-utils pkg-plist Makefile

devel/ignition-utils: New port: General-purpose classes and functions for Gazebo projects
DeltaFile
+60-0devel/ignition-utils/pkg-plist
+29-0devel/ignition-utils/Makefile
+3-0devel/ignition-utils/distinfo
+2-0devel/ignition-utils/pkg-descr
+1-0devel/Makefile
+95-05 files

FreeBSD/ports 1496fbcdevel/ignition-tools Makefile pkg-plist

devel/ignition-tools: update 1.5.0 → 2.0.3
DeltaFile
+6-10devel/ignition-tools/Makefile
+9-0devel/ignition-tools/pkg-plist
+3-3devel/ignition-tools/distinfo
+18-133 files

FreeBSD/ports 31af8acmath/py-cvxpy Makefile distinfo, math/py-cvxpy/files patch-pyproject.toml

math/py-cvxpy: update 1.6.4 → 1.9.0
DeltaFile
+12-14math/py-cvxpy/Makefile
+13-0math/py-cvxpy/files/patch-pyproject.toml
+3-3math/py-cvxpy/distinfo
+28-173 files

FreeBSD/ports 822577edevel/ignition-plugin pkg-plist Makefile

devel/ignition-plugin: update 1.4.0 → 4.0.0
DeltaFile
+57-68devel/ignition-plugin/pkg-plist
+6-4devel/ignition-plugin/Makefile
+3-3devel/ignition-plugin/distinfo
+66-753 files

FreeBSD/ports 7576a23devel/ignition-common pkg-plist Makefile

devel/ignition-common: update 3.17.1 → 7.0.0
DeltaFile
+194-238devel/ignition-common/pkg-plist
+12-10devel/ignition-common/Makefile
+3-3devel/ignition-common/distinfo
+209-2513 files

FreeBSD/ports 585e940devel/ignition-cmake pkg-plist Makefile, devel/ignition-cmake/files patch-cmake_FindAVCODEC.cmake patch-cmake_FindAVDEVICE.cmake

devel/ignition-cmake: update 2.18.0 → 5.0.0
DeltaFile
+87-80devel/ignition-cmake/pkg-plist
+8-3devel/ignition-cmake/Makefile
+4-3devel/ignition-cmake/files/patch-cmake_FindAVCODEC.cmake
+4-3devel/ignition-cmake/files/patch-cmake_FindAVDEVICE.cmake
+4-3devel/ignition-cmake/files/patch-cmake_FindAVFORMAT.cmake
+4-3devel/ignition-cmake/files/patch-cmake_FindAVUTIL.cmake
+111-952 files not shown
+118-1018 files

FreeBSD/ports f4749a0misc/py-gguf distinfo Makefile

misc/py-gguf: update 0.18.0.8913 → 0.19.0.9222
DeltaFile
+3-3misc/py-gguf/distinfo
+2-3misc/py-gguf/Makefile
+5-62 files

FreeBSD/ports b353264security/cowrie distinfo Makefile

security/cowrie: update 2.9.17 → 2.9.19
DeltaFile
+3-3security/cowrie/distinfo
+1-1security/cowrie/Makefile
+4-42 files

FreeBSD/ports 2ff410amisc/llama-cpp Makefile distinfo

misc/llama-cpp: update 9159 → 9222
DeltaFile
+10-18misc/llama-cpp/Makefile
+3-5misc/llama-cpp/distinfo
+0-1misc/llama-cpp/pkg-plist
+13-243 files

FreeBSD/ports fccbc75math Makefile, math/py-sparsediffpy Makefile distinfo

math/py-sparsediffpy: New port: Python bindings for SparseDiffEngine algorithmic differentiation
DeltaFile
+23-0math/py-sparsediffpy/Makefile
+3-0math/py-sparsediffpy/distinfo
+2-0math/py-sparsediffpy/pkg-descr
+1-0math/Makefile
+29-04 files

FreeBSD/ports a3b0247devel/py-monty distinfo Makefile

devel/py-monty: update 2026.2.18 → 2026.5.18
DeltaFile
+3-3devel/py-monty/distinfo
+1-3devel/py-monty/Makefile
+4-62 files

FreeBSD/ports 90732a0science/libcifpp distinfo Makefile

science/libcifpp: update 10.0.3 → 10.0.4
DeltaFile
+5-5science/libcifpp/distinfo
+2-2science/libcifpp/Makefile
+1-1science/libcifpp/pkg-plist
+8-83 files

FreeBSD/ports 50f3372math/py-osqp Makefile distinfo, math/py-osqp/files patch-CMakeLists.txt

math/py-osqp: update 0.6.2.post5 → 1.1.1
DeltaFile
+28-0math/py-osqp/files/patch-CMakeLists.txt
+18-8math/py-osqp/Makefile
+7-3math/py-osqp/distinfo
+53-113 files

FreeBSD/ports 2a17b72misc/py-comfy-aimdo distinfo Makefile

misc/py-comfy-aimdo: update 0.4.2 → 0.4.3
DeltaFile
+3-3misc/py-comfy-aimdo/distinfo
+1-1misc/py-comfy-aimdo/Makefile
+4-42 files

FreeBSD/ports c90cfb1misc/comfy-cli distinfo Makefile

misc/comfy-cli: update 1.8.0 → 1.10.0
DeltaFile
+3-3misc/comfy-cli/distinfo
+1-1misc/comfy-cli/Makefile
+4-42 files

FreeBSD/ports 93a9d0cmath/R-cran-GPArotation distinfo Makefile

math/R-cran-GPArotation: Update to 2026.4-1

Changelog: https://cran.r-project.org/web/packages/GPArotation/NEWS
DeltaFile
+3-3math/R-cran-GPArotation/distinfo
+1-1math/R-cran-GPArotation/Makefile
+4-42 files

FreeBSD/ports 2bec305www/freenginx-acme distinfo Makefile

www/freenginx-acme: update freenginx distibution version

Bump PORTREVISION.

Sponsored by:   tipi.work
DeltaFile
+3-3www/freenginx-acme/distinfo
+1-0www/freenginx-acme/Makefile
+4-32 files

FreeBSD/ports 3821218www/freenginx-devel distinfo version.mk

www/freenginx-devel: update: 1.31.0 -> 1.31.1

Sponsored by:   tipi.work

<ChangeLog>

*) Feature: the "off" parameter of the "index" directive.
   Thanks to Fabiano Furtado.

*) Bugfix: a segmentation fault might occur in a worker process if the
   "rewrite" directive was used to change request arguments and other
   directives of the ngx_http_rewrite_module were executed afterwards.

*) Bugfix: in the "set" directive.

*) Bugfix: a segmentation fault might occur in a worker process if the
   ngx_http_charset_module was used to convert responses from UTF-8.

*) Bugfix: in the ngx_http_charset_module.

    [12 lines not shown]
DeltaFile
+3-3www/freenginx-devel/distinfo
+1-1www/freenginx-devel/version.mk
+0-1www/freenginx-devel/Makefile
+4-53 files

FreeBSD/ports 4f3c97awww/freenginx-devel distinfo Makefile.extmod

www/freenginx-devel: update njs 0.9.8 -> 0.9.9 (+)

Bump PORTREVISION.

<ChangeLog>

nginx modules:

*) Security: a heap buffer overflow might occur in a worker process
   when the "js_fetch_proxy" directive value contains nginx
   variables derived from the client request ($http_*, $arg_*,
   $cookie_*, etc.) and the location's JS handler invokes
   ngx.fetch(). The issue was introduced in dea83189 (0.9.4).

*) Feature: added js_access directive.

*) Feature: added r.readRequestText(), r.readRequestArrayBuffer(),
   and r.readRequestJSON() - async methods that read the request
   body, available in js_access and js_content directives.

    [19 lines not shown]
DeltaFile
+3-3www/freenginx-devel/distinfo
+1-1www/freenginx-devel/Makefile.extmod
+1-0www/freenginx-devel/Makefile
+5-43 files

FreeBSD/ports ac43d62www/nginx-acme distinfo Makefile, www/nginx-devel distinfo version.mk

www/nginx-devel: Update to 1.31.0

Changes with nginx 1.31.0                                        13 May
2026

    *) Security: when using the "proxy_set_body" directive, an attacker
       might inject data in the proxied request to an HTTP/2 backend
       (CVE-2026-42926).
       Thanks to Mufeed VH of Winfunc Research.

    *) Security: a heap memory buffer overflow might occur in a worker
       process while handling a specially crafted request by
       ngx_http_rewrite_module, potentially resulting in arbitrary code
       execution (CVE-2026-42945).
       Thanks to Leo Lin.

    *) Security: a heap memory buffer overread might occur in a worker
       process while handling a specially crafted response by
       ngx_http_scgi_module or ngx_http_uwsgi_module, allowing an

    [69 lines not shown]
DeltaFile
+3-3www/nginx-devel/distinfo
+3-3www/nginx-acme/distinfo
+1-1www/nginx-acme/Makefile
+1-1www/nginx-devel/version.mk
+8-84 files