Fedora has issued an advisory today (April 6): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/I542F7XFKEQAXTU6EJ5HALNME3SSCJ4T/ It has no details about the security issues fixed.
No one packager in view for zchunk, so assigning this globally.
Status comment: (none) => fixed upstream in 1.3.1Assignee: bugsquad => pkg-bugs
Looked through the upstream commits between 1.2.4 and 1.3.1, basically only security fixes, tested build and basic usage, and pushed to cauldron
Resolution: (none) => FIXEDStatus: NEW => RESOLVED