Skip to content

frigate

v0.17.2 Security

This release includes 9 security fixes for security teams reviewing exposed deployments.

Published 28d Home Automation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 9 known CVEs

Topics

ai camera google-coral home-assistant home-automation homeautomation
+6 more
mqtt nvr object-detection realtime rtsp tensorflow

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Updates All Commits, Images, and Notable Changes across a mixed release.

Full changelog

This is a maintenance release for Frigate 0.17 that includes fixes and minor changes.

Images

What's Changed

Security Advisories

These advisories impact users with publicly exposed instances with no authentication and users with viewer roles where it is important to restrict access to some cameras.

Notable Changes

  • Exports can optionally include recording segment information as chapters in mp4 metadata
  • Performance improvements when displaying previews in the live page

All Commits

  • Update docs for DEIMv2 support by @NickM-27 in https://github.com/blakeblackshear/frigate/pull/22598
  • Add role-based auth to websocket message handler by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/22710
  • Update MemryX section documentation by @abinila4 in https://github.com/blakeblackshear/frigate/pull/22712
  • Memryx docs update by @abinila4 in https://github.com/blakeblackshear/frigate/pull/22746
  • Docs update by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/22864
  • Update restream.md docs and clarify output config by @Feni85 in https://github.com/blakeblackshear/frigate/pull/22860
  • Fix broken docs links with hash fragments that resolve wrong on reload by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/22925
  • Fix yolonas colab notebook by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/22936
  • Fixes by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23235
  • Add metadata for creation time in recordings / exports by @NickM-27 in https://github.com/blakeblackshear/frigate/pull/23239
  • Fix admin response cache leak to non-admin users via nginx proxy_cache by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23261
  • Docs update by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23280
  • Docs update by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23282
  • Filter motion review by allowed cameras by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23294
  • Add ability to control chapters set on MP4 Export by @NickM-27 in https://github.com/blakeblackshear/frigate/pull/23310
  • Chapter tweaks by @NickM-27 in https://github.com/blakeblackshear/frigate/pull/23440
  • Catch edge cases in security protections by @NickM-27 in https://github.com/blakeblackshear/frigate/pull/23493
  • Offload preview encoding and Plus upload off the API event loop by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23552
  • Fix cache control header for current hour preview mp4s by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23553
  • Allow non-admin users to use PTZ controls for cameras they have access to by @hawkeye217 in https://github.com/blakeblackshear/frigate/pull/23578

New Contributors

  • @Feni85 made their first contribution in https://github.com/blakeblackshear/frigate/pull/22860

Full Changelog: https://github.com/blakeblackshear/frigate/compare/v0.17.1...v0.17.2

Security Fixes

  • GHSA-hh3j-7g2f-43j2 — go2rtc WebSocket live stream camera access bypass for role‑restricted users
  • GHSA-pqfr-m69j-4mq2 — Incomplete patch of CVE-2025-62382: backslash‑separator bypass leading to arbitrary host‑file read via shutil.copy
  • GHSA-r57j-5jm9-hpcc — Incomplete patch of CVE-2026-25643: go2rtc exec prefix block bypass enabling RCE and container escape
  • GHSA-4vfc-hxpj-f7x7 — RTSP credentials leak to viewer role via nginx proxy_cache
  • GHSA-wwww-5h25-jf98 — Authenticated Admin can achieve RCE via go2rtc Stream API due to missing exec filter enforcement
  • GHSA-c4qf-xxq4-vf55 — Authenticated viewer can read /api/logs endpoints exposing admin password and camera credentials (privilege escalation)
  • GHSA-74x4-gw64-2mq5 — Camera ACL bypass via Nginx static locations allowing access to unauthorized recordings
  • GHSA-mgh5-cr9h-g6hr — Viewer‑Role user can access go2rtc internal API for sensitive information
  • GHSA-r5fm-h944-8chq — WebSocket missing authorization permitting viewer to execute admin‑only operations

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track frigate

Get notified when new releases ship.

Sign up free

About frigate

NVR with realtime local object detection for IP cameras

All releases →

Related context

Beta — feedback welcome: [email protected]