mercurial (6.3.2-1+deb12u1) bookworm-security; urgency=high
* CVE-2025-2361: reflected XSS in hgweb (closes: #
1100899)
* patchbomb: don't test ambiguous address (fixes FTBFS after python's
fix for CVE-2023-27043).
[dgit import unpatched mercurial 6.3.2-1+deb12u1]