This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 6d
Media Servers
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
self-hosted
youtube
youtube-dl
yt-dlp
Affected surfaces
rbac
rce_ssrf
Summary
AI summaryUpdates fix, e061a8a, and feat across a mixed release.
Full changelog
Docker Images
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.07.21
GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.07.21
Changes
- feat: ALLOW_PRIVATE_ADDRESSES to opt out of the SSRF checks (closes #1036) (e061a8a)
- docs: document the SSRF guard's connect-time coverage limitations (13cb65d)
- fix: re-validate outbound connections at fetch time against internal hosts (1b02a99)
- fix: fail closed when an SSRF-guarded host cannot be resolved (ebcfe57)
- fix: enforce download-dir containment at the resolved-path chokepoint (3bd2c3e)
- ci: update releases in place instead of delete-and-recreate (707f700)
- chore: rework issue and discussion templates around scope policy (c519f45)
Security Fixes
- Re-validate outbound connections at fetch time against internal hosts
- Fail closed when an SSRF-guarded host cannot be resolved
- Enforce download-dir containment at the resolved-path chokepoint
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About metube
Self-hosted video downloader for YouTube and other sites (web UI for youtube-dl / yt-dlp)
Related context
Related tools
Beta — feedback welcome: [email protected]