This release includes 1 security fix for security teams reviewing exposed deployments.
Published 6d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
hotwire
kanban
rails
ruby
Affected surfaces
rce_ssrf
Summary
AI summaryBlock IPv6 addresses reaching internal IPs in the SSRF guard and fix Stimulus event listener leakage.
Full changelog
What's Changed
- Tag all pushes to main as 'latest' in Docker by @monorkin in https://github.com/basecamp/fizzy/pull/2986
- Block IPv6 addresses that reach internal IPs in the SSRF guard by @djmb in https://github.com/basecamp/fizzy/pull/2988
- Fix BC-10091759496: stop leaking event listeners across Stimulus connect/disconnect by @jeremy in https://github.com/basecamp/fizzy/pull/2978
Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@d3a3998
Security Fixes
- SSRF guard now blocks IPv6 addresses that reach internal IPs
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]