This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalVersion 7.2.0 removes Pocket sharing and hardens SSRF/DDoS defenses while adding feed icons and starred‑entry search.
Why it matters: Security severity 90 blocks arbitrary URL access in the image proxy and adds ULA/CGNAT blocking, directly reducing SSRF exposure; deprecation severity 70 eliminates the Pocket feature entirely.
Summary
AI summaryRemoved Pocket sharing, added feed icon support, search for starred entries, and enhanced SSRF/DDoS protections.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Prevents image proxy from accessing arbitrary URLs to avoid SSRF attacks. Prevents image proxy from accessing arbitrary URLs to avoid SSRF attacks. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Strengthens SSRF protection by blocking ULA and CGNAT ranges. Strengthens SSRF protection by blocking ULA and CGNAT ranges. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
Prevents DDOS attacks by filtering OPML files during imports. Prevents DDOS attacks by filtering OPML files during imports. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds support for icons declared in feeds. Adds support for icons declared in feeds. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Search now also works for starred entries. Search now also works for starred entries. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Performance | Low |
Improves performance of the feed refresh engine. Improves performance of the feed refresh engine. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Deprecation | High |
Removes Pocket sharing feature due to service discontinuation. Removes Pocket sharing feature due to service discontinuation. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes proper display of error message when subscribing to a feed. Fixes proper display of error message when subscribing to a feed. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
- Add support for icons declared in feeds. This is useful for feeds exposed by RSS bridges (#2048)
- Search now also works for starred entries (#2217)
- The error message when subscribing to a feed is now properly displayed again
- Small performance improvements to the feed refresh engine
- Removed the Pocket sharing feature because the Pocket service has been discontinued
- Prevent the image proxy feature to access any URL to avoid SSRF attacks
- Strengthened the SSRF protection by also blocking ULA and CGNAT ranges
- Prevent DDOS attacks by filtering OPML files during imports
Breaking Changes
- Removed the Pocket sharing feature because the Pocket service has been discontinued
Security Fixes
- Prevent image proxy from accessing arbitrary URLs to avoid SSRF attacks
- Strengthened SSRF protection by blocking ULA and CGNAT ranges
- Prevent DDOS attacks by filtering OPML files during imports
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]