diff --git a/www/changelog.xml b/www/changelog.xml
index fe87c01d..4abfedf7 100644
--- a/www/changelog.xml
+++ b/www/changelog.xml
@@ -26,8 +26,15 @@
- Add --os switch to report a different OS type to the gateway.
- Support new XML POST format.
- - Fix buffer overflow on long Location: and Set-Cookie: headers sent from server.
- Add SecurID token support using libstoken.
+
+
+ OpenConnect v4.08
+ (PGP signature) — 2013-02-13
+
+ - Fix overflow on HTTP request buffers (CVE-2012-6128)
+ - Fix connection to servers with round-robin DNS with two-stage auth/connect.
+ - Impose minimum MTU of 1280 bytes.
- Fix some harmless issues reported by Coverity.
- Improve "Attempting to connect..." message to be explicit when it's connecting to a proxy.