New comment by subnut on void-packages repository https://github.com/void-linux/void-packages/pull/36561#issuecomment-1098115373 Comment: We ship that same 2014 version of mongoose in our repos! :fearful: ``` $ xbps-query -Rf smplayer | grep bin /usr/bin/simple_web_server /usr/bin/smplayer ``` There have been many CVEs since then - https://www.cvedetails.com/vulnerability-list/vendor_id-16334/product_id-41402/Cesanta-Mongoose.html