diff --git a/NEWS b/NEWS
index 2dc2de54a9c8394ee4f942c79c02e7701a651a80..b90fd80848d2782762c97c9d793676e127db80e1 100644
--- a/NEWS
+++ b/NEWS
@@ -54,6 +54,7 @@ Misc:
 
 3rd party libraries (contrib):
  * Update FFmpeg to 4.4
+ * Update libflac to 1.3.4 to fix CVE-2020-0499 and CVE-2021-0561
  * Update libsmb2 to fix invalid UTF-8 encoding of some filenames
  * Update taglib to fix corruptions when editing some OGG metadata
  * Update dav1d to 0.9.2