update changelog to reflex new upstream version and associated CVE number