More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2376845 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This was already fixed in 1.26.3 released on 06/27: https://bodhi.fedoraproject.org/updates/FEDORA-2025-de9e1b47db What's the point in opening this?
*** Bug 2377060 has been marked as a duplicate of this bug. ***