Can upstream help to backport CVE-2025-6176 fix for 1.0.9 release?
Author: pnemadeCreated Jan 5, 2026Updated Apr 8, 2026
Hi, I see that brotli-1.0.9 is C++ code and later releases are pure C code. We saw CVE-2025-6176 fix in 1.2.0 release but there are still many linux distributions which are using brotli-1.0.9 release. Is it possible for upstream to provide this CVE fix patch release for brotli-1.0.9 ?
Source: google/brotli