CVE-2026-66754: rouille: remove_prefix function that allows remote unauthenticated
attackers to crash the server by sending a crafted percent-encoded URL (bsc#1273884).
CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding
Desynchronization (bsc#1273886).