OpenBSD/ports Lwgj5Si — security/gnupg Makefile distinfo, security/gnupg/patches patch-g10_import_c

   Reattempt the upgrade to gnupg-2.5.24

   Upstream published a fix for regression that broke mail/notmuch
   configure. Updating now means smaller steps if we need an update for
   a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@
VersionDeltaFile
1.1+19-0security/gnupg/patches/patch-g10_import_c
1.58+2-2security/gnupg/distinfo
1.154+2-1security/gnupg/Makefile
+23-33 files

OpenBSD/ports m3H7lWy — www/chromium distinfo, www/chromium/patches patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc

   update to 154.0.8037.92; ok naddy@
VersionDeltaFile
1.498+4-4www/chromium/distinfo
1.6+2-2www/chromium/patches/patch-third_party_test_fonts_fontconfig_BUILD_gn
1.5+2-2www/chromium/patches/patch-third_party_fontconfig_include_meson-config_h
1.5+2-2www/chromium/patches/patch-content_browser_web_contents_web_contents_impl_cc
1.24+1-1www/chromium/patches/patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc
1.39+1-1www/chromium/patches/patch-gpu_command_buffer_service_gles2_cmd_decoder_cc
+12-123 files not shown
+14-149 files

OpenBSD/ports eo4oRVn — lang/python/3 Makefile, lang/python/3/patches patch-Modules__ssl_c

   cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
   server-side SSLContext when sni_callback switches contexts. ok tb kmos
VersionDeltaFile
1.6.2.1+56-25lang/python/3/patches/patch-Modules__ssl_c
1.25.2.3+1-0lang/python/3/Makefile
+57-252 files

OpenBSD/ports QTrl6WC — lang/python/3 Makefile, lang/python/3/patches patch-Modules__ssl_c

   cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
   server-side SSLContext when sni_callback switches contexts. ok tb kmos

   A remote, unauthenticated TLS client can make a server crash or call
   through a freed pointer if its sni_callback assigns a different context
   to SSLSocket.context (the documented way to select a certificate per
   server name) and nothing else keeps the original ssl.SSLContext alive.
   Typical cases are servers that create an SSLContext per connection or
   replace it while connections are open.
VersionDeltaFile
1.6+84-6lang/python/3/patches/patch-Modules__ssl_c
1.35+1-0lang/python/3/Makefile
+85-62 files

OpenBSD/ports JCxKe70 — net/libtorrent distinfo Makefile, net/libtorrent/patches patch-test_Makefile_in

   update net/libtorrent 0.16.24

   - major bump due to removed symbols
   - unbreaks tests by linking using static archive (from tj@)

   approved by sthen@ and tested by and OK tj@
VersionDeltaFile
1.9+25-9net/libtorrent/patches/patch-test_Makefile_in
1.75+2-3net/libtorrent/Makefile
1.25+2-2net/libtorrent/distinfo
+29-143 files

OpenBSD/ports xwTjQsY — net/rtorrent Makefile distinfo, net/rtorrent/patches patch-test_Makefile_in

   update net/rtorrent 0.16.24

   - various security fixes (e.g., overflow, heap overflow and use-after-free)
   - regen test/Makefile.in patch to remove a new, third instance of -ldl

   approved by sthen@ and tested by and OK tj@
VersionDeltaFile
1.11+4-1net/rtorrent/patches/patch-test_Makefile_in
1.25+2-2net/rtorrent/distinfo
1.81+1-2net/rtorrent/Makefile
+7-53 files

OpenBSD/ports fdSivOC — databases/p5-DBI Makefile distinfo, databases/p5-DBI/patches patch-DBI_xs

   Update p5-DBI to 1.654

   1.654 - 2026-09-25, H.Merijn Brand & Robert Rothenberg
       * Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
       * Fix FetchHashKeyName   on IV/NV (CVE-2026-88816) (reported by Raj)
       * Fix provided in META

   With upstream patch for compilation under gcc.

   ok sthen@
VersionDeltaFile
1.3+18-23databases/p5-DBI/patches/patch-DBI_xs
1.36+2-2databases/p5-DBI/distinfo
1.78+1-1databases/p5-DBI/Makefile
+21-263 files

OpenBSD/ports Fr9aOuY — net/knot Makefile

   There is a hidden dep on databases/libhiredis that can cause a build
   failure when junking between configure and build.  Since enabling this
   feature changes PLIST, disable for now and we can re-evaluate after
   unlock.

   OK lucas@ naddy@
VersionDeltaFile
1.90+2-0net/knot/Makefile
+2-01 files

OpenBSD/ports u24A4Bd — mail/mozilla-thunderbird Makefile distinfo

   mail/mozilla-thunderbird: update to 140.17.0.

   see https://www.thunderbird.net/en-US/thunderbird/140.17.0esr/releasenotes/
VersionDeltaFile
1.312.2.10+2-2mail/mozilla-thunderbird/distinfo
1.525.2.10+1-1mail/mozilla-thunderbird/Makefile
+3-32 files

OpenBSD/ports Ta2EUnK — mail/mozilla-thunderbird Makefile distinfo, mail/thunderbird-i18n Makefile.inc distinfo

   mail/mozilla-thunderbird: update to 153.4.0.

   see https://www.thunderbird.net/en-US/thunderbird/153.4.0esr/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-101/ (404)
VersionDeltaFile
1.311+132-132mail/thunderbird-i18n/distinfo
1.328+2-2mail/mozilla-thunderbird/distinfo
1.285+1-1mail/thunderbird-i18n/Makefile.inc
1.543+1-1mail/mozilla-thunderbird/Makefile
+136-1364 files

OpenBSD/ports cxfipPX — textproc/groff Makefile, textproc/groff/patches patch-src_roff_troff_input_cpp patch-src_preproc_html_pre-html_cpp

   MFC "Backport three security fixes from the groff-1.24.2 release", ok schwarze@
VersionDeltaFile
1.52.12.1+1-1textproc/groff/Makefile
1.3.2.1+0-0textproc/groff/patches/patch-src_roff_troff_input_cpp
1.1.2.1+0-0textproc/groff/patches/patch-src_preproc_html_pre-html_cpp
1.1.2.1+0-0textproc/groff/patches/patch-src_devices_gropdf_pdfmom_pl
1.1.2.1+0-0textproc/groff/patches/patch-contrib_mm_mmroff_pl
+1-15 files

OpenBSD/ports T0mnlFj — graphics/png distinfo Makefile, graphics/png/patches patch-Makefile_in

   update to png-1.6.59
   https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j
VersionDeltaFile
1.150.2.1+6-3graphics/png/Makefile
1.6.4.1+3-3graphics/png/patches/patch-Makefile_in
1.79.2.1+2-2graphics/png/distinfo
+11-83 files

OpenBSD/ports BKXvJP0 — graphics/png distinfo Makefile, graphics/png/patches patch-Makefile_in

   update to png-1.6.59, fixing use-after-free of zlib input in
   png_read_end() after incomplete zTXt, iTXt or iCCP decompression
   https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j

   ok matthieu who has verified that this is not reachable from xenocara's
   use of the static-linked copy
VersionDeltaFile
1.151+6-3graphics/png/Makefile
1.7+3-3graphics/png/patches/patch-Makefile_in
1.80+2-2graphics/png/distinfo
+11-83 files

OpenBSD/ports tzUvWuF — sysutils/telegraf Makefile, sysutils/telegraf/patches patch-plugins_inputs_unbound_unbound_go patch-plugins_inputs_nsd_nsd_go

   set -u _nsd / _unbound as appropriate when running nsd-control /
   unbound-control through doas, to match the existing pkg-readme.
   from Atanas Vladimirov.
VersionDeltaFile
1.3+6-3sysutils/telegraf/pkg/README
1.6+4-2sysutils/telegraf/patches/patch-plugins_inputs_unbound_unbound_go
1.4+4-2sysutils/telegraf/patches/patch-plugins_inputs_nsd_nsd_go
1.48+2-0sysutils/telegraf/Makefile
+16-74 files

OpenBSD/ports ytOzOeq — meta/tor-browser Makefile, www/tor-browser Makefile.inc

   Tor Browser: update to 15.0.24
VersionDeltaFile
1.118.2.9+6-6www/tor-browser/browser/distinfo
1.67.2.8+2-2www/tor-browser/noscript/distinfo
1.124.2.9+2-2meta/tor-browser/Makefile
1.74.2.8+1-1www/tor-browser/noscript/Makefile
1.197.2.9+1-1www/tor-browser/browser/Makefile
1.121.2.9+1-1www/tor-browser/Makefile.inc
+13-136 files

OpenBSD/ports eQ1CBAh — meta/tor-browser Makefile, www/tor-browser Makefile.inc

   Tor Browser: update to 15.0.24

   OK naddy@
VersionDeltaFile
1.133+6-6www/tor-browser/browser/distinfo
1.77+2-2www/tor-browser/noscript/distinfo
1.138+2-2meta/tor-browser/Makefile
1.84+1-1www/tor-browser/noscript/Makefile
1.216+1-1www/tor-browser/browser/Makefile
1.135+1-1www/tor-browser/Makefile.inc
+13-136 files

OpenBSD/ports TcDrRW9 — games/devilutionx Makefile, games/devilutionx/patches patch-Source_dvlnet_tcp_server_cpp

   missed cvs add to go with devilutiomx/Makefile r1.21, unbreaking
   newer asio. from Brad.
VersionDeltaFile
1.1+15-0games/devilutionx/patches/patch-Source_dvlnet_tcp_server_cpp
1.23+1-1games/devilutionx/Makefile
+16-12 files

OpenBSD/ports rtreQij — textproc/groff Makefile, textproc/groff/patches patch-contrib_mm_mmroff_pl patch-src_preproc_html_pre-html_cpp

   Backport three security fixes from the groff-1.24.2 release.
   OK naddy@ on a previous, minimally different version of this patch.

   From the groff-1.24.2 release announcement (September 28, 2026):
   "This release corrects command injection security vulnerabilities
   (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs.  The last of
   these is a preprocessor that is run when groff or troff is run with the
   -T html or -T xhtml options.  The vulnerabilities are variously
   14-26 years old.  Malicious input can escape groff's default "safer"
   mode, running commands embedded in that input at the user's privilege
   level.  The groff development team recommends this release to any users
   who employ the named tools or GNU troff output formats with untrusted
   inputs.
   Man page rendering is not vulnerable unless rendering (X)HTML."
VersionDeltaFile
1.1+82-0textproc/groff/patches/patch-src_devices_gropdf_pdfmom_pl
1.3+35-12textproc/groff/patches/patch-src_roff_troff_input_cpp
1.1+39-0textproc/groff/patches/patch-src_preproc_html_pre-html_cpp
1.1+24-0textproc/groff/patches/patch-contrib_mm_mmroff_pl
1.53+1-1textproc/groff/Makefile
+181-135 files

OpenBSD/ports ZIx0pWO — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static links against security/openssl/3.5 in -stable
VersionDeltaFile
1.56.2.3+1-1sysutils/borgbackup/2.0/Makefile
1.86.2.3+1-1security/sslscan/Makefile
1.281.2.8+1-0mail/postfix/stable/Makefile
+3-23 files

OpenBSD/ports mJSFADA — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   MFC: Update to OpenSSL 3.5.9

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.7.2.3+2-2security/openssl/3.5/distinfo
1.16.2.3+1-1security/openssl/3.5/Makefile
1.7.2.3+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports Pd8bpzp — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static link against security/openssl/3.5
VersionDeltaFile
1.64+2-0sysutils/borgbackup/2.0/Makefile
1.90+1-0security/sslscan/Makefile
1.289+1-0mail/postfix/stable/Makefile
+4-03 files

OpenBSD/ports Qu9OKte — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   Update to OpenSSL 3.5.9, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.10+2-2security/openssl/3.5/distinfo
1.19+1-1security/openssl/3.5/Makefile
1.10+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports f8r12LY — security/openssl/4.0 Makefile distinfo, security/openssl/4.0/pkg PLIST

   Update to openssl 4.0.3, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-4.0.3
VersionDeltaFile
1.5+2-2security/openssl/4.0/distinfo
1.8+1-1security/openssl/4.0/Makefile
1.5+2-0security/openssl/4.0/pkg/PLIST
+5-33 files

OpenBSD/ports Y4x5oOe — net/haproxy Makefile distinfo

   MFC: net/haproxy: update to 3.2.25

   Changes:
   https://www.haproxy.org/download/3.2/src/CHANGELOG

   from Mark Patruck
   ok sthen
VersionDeltaFile
1.93.2.6+2-2net/haproxy/distinfo
1.134.2.6+1-1net/haproxy/Makefile
+3-32 files

OpenBSD/ports Bt27Miq — net/haproxy Makefile distinfo

   net/haproxy: update to 3.2.25

   Changes:
   https://www.haproxy.org/download/3.2/src/CHANGELOG

   from Mark Patruck
   ok sthen
VersionDeltaFile
1.100+2-2net/haproxy/distinfo
1.141+1-1net/haproxy/Makefile
+3-32 files

OpenBSD/ports QD7Ipiv — www/mozilla-firefox distinfo, www/mozilla-firefox/patches patch-security_nss_lib_nss_nss_h patch-third_party_rust_nss-rs__cargo-checksum_json

   www/mozilla-firefox: MFC update to 157.0.

   see https://www.firefox.com/en-US/firefox/157.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/
VersionDeltaFile
1.1.4.1+18-0www/mozilla-firefox/patches/patch-netwerk_socket_neqo_glue_src_lib_rs
1.1.2.1+16-0www/mozilla-firefox/patches/patch-security_manager_ssl_EnabledSignatureSchemes_h
1.1.2.1+15-0www/mozilla-firefox/patches/patch-third_party_rust_nss-rs_src_constants_rs
1.1.2.1+9-0www/mozilla-firefox/patches/patch-third_party_rust_nss-rs__cargo-checksum_json
1.1.6.7+2-2www/mozilla-firefox/patches/patch-security_nss_lib_nss_nss_h
1.397.2.22+2-2www/mozilla-firefox/distinfo
+62-47 files not shown
+66-813 files

OpenBSD/ports UqS89bh — www/firefox-esr Makefile distinfo

   www/firefox-esr: update to 140.17.0.

   see https://www.firefox.com/en-US/firefox/140.17.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-99/

   last planned release in esr140 branch
VersionDeltaFile
1.180.2.8+4-4www/firefox-esr/distinfo
1.270.2.8+2-2www/firefox-esr/Makefile
+6-62 files

OpenBSD/ports FQIyF51 — www/firefox-esr Makefile distinfo, www/firefox-esr-i18n Makefile.inc distinfo

   www/firefox-esr: update to 153.4.0.

   see https://www.firefox.com/en-US/firefox/153.4.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/

   ok naddy@
VersionDeltaFile
1.185+162-162www/firefox-esr-i18n/distinfo
1.190+4-4www/firefox-esr/distinfo
1.282+2-3www/firefox-esr/Makefile
1.197+1-1www/firefox-esr-i18n/Makefile.inc
+169-1704 files

OpenBSD/ports QcMMlzW — www/firefox-i18n Makefile.inc distinfo, www/mozilla-firefox distinfo Makefile

   www/mozilla-firefox: update to 157.0.

   see https://www.firefox.com/en-US/firefox/157.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/

   bump REVISION to be ahead of 7.9-stable

   ok naddy@
VersionDeltaFile
1.409+164-164www/firefox-i18n/distinfo
1.423+4-4www/mozilla-firefox/distinfo
1.712+4-4www/mozilla-firefox/Makefile
1.364+1-1www/firefox-i18n/Makefile.inc
+173-1734 files

OpenBSD/ports hXBNbbY — net/libslirp Makefile distinfo, net/libslirp/patches patch-src_tcp_subr_c patch-src_tcp_input_c

   net/libslirp: update to 4.9.5

   Addressed CVE-2026-95507 and CVE-2026-95508

   OK: sthen@
VersionDeltaFile
1.4+2-2net/libslirp/distinfo
1.5+1-1net/libslirp/Makefile
1.2+0-0net/libslirp/patches/patch-src_tcp_subr_c
1.2+0-0net/libslirp/patches/patch-src_tcp_input_c
1.2+0-0net/libslirp/patches/patch-src_slirp_c
1.2+0-0net/libslirp/patches/patch-meson_build
+3-31 files not shown
+3-37 files