This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Communication & Email
✓ No known CVEs patched
This release patches 1 known CVE
Topics
email-testing
go
mailpit
pop3-server
smtp-relay
smtp-server
+1 more
smtp-testing
Affected surfaces
rce_ssrf
Summary
AI summaryUpdates Chore, Feature, and Fix across a mixed release.
Full changelog
This release includes an important security fixes, so upgrading is strongly recommended.
This release includes a security fix which closes an additional IPv6 address bypasses that could allow the Link Check API to reach internal services or cloud metadata endpoints.
Security
- Fix incomplete SSRF protection in IsInternalIP() detection for IPv6 transition mechanisms (GHSA-w4mc-hhc6-xp28)
Feature
- Add wait support to readyz (#697)
Chore
- Compress websocket messages once per broadcast to improve performance (#695)
- Toggle websocket compression using HTTP compression setting (#695)
- Update Github Actions dependencies
- Update Go dependencies
- Update node dependencies
Fix
- Adjust header setting order in error response functions (#699)
Test
- Add readyz tests
Security Fixes
- GHSA-w4mc-hhc6-xp28 — Fix incomplete SSRF protection in IsInternalIP() detection for IPv6 transition mechanisms
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]