Files
Martin Vogel 1d30971ff0 Bump vendored deps: Mongoose 7.21, SQLite 3.51.3, mimalloc 3.2.8
Mongoose 7.20 → 7.21:
  Fixes 3 CVEs disclosed 2026-04-02:
  - CVE-2026-5244: preauth RCE via TLS heap buffer overflow
  - CVE-2026-5245: mDNS stack overflow RCE (34-byte UDP packet)
  - CVE-2026-5246: mTLS bypass with P-384 certificates

SQLite 3.49.1 → 3.51.3:
  Fixes WAL-reset database corruption bug (we use WAL mode).
  Also fixes nested EXISTS query errors, POSIX lock deadlock,
  and FTS5 memory error.

mimalloc 2.1.9 → 3.2.8 (v2 → v3):
  Eliminated thread-local segments for better cross-thread sharing,
  lower fragmentation, faster TLS on Windows, improved calloc.
  API change: mi_option_eager_commit → mi_option_arena_eager_commit.

Linux kernel benchmark: 1:42 (no regression). All 2718 tests pass.
2026-04-03 23:01:06 +02:00

9.0 MiB

The file is too large to be shown. View Raw