Skip to content

PeerTube

v8.2.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 25d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

activitypub angular decentralized p2p video

Summary

AI summary

Security hardening and multiple bug fixes, including UUID handling and caption management.

Full changelog

We strongly recommend all administrators upgrade immediately.

SECURITY

This release addresses vulnerabilities ranging from medium to high severity affecting PeerTube <= 8.2.1. Security hardening is also included.
In a few weeks, this changelog will be updated to disclose the vulnerabilities.

Bug fixes

  • Accept short UUIDs for loadByIdOrUUID and loadByIdOrUUIDWithFiles plugin helpers
  • Allow restricted embed to be displayed on the origin instance
  • Fix invalid state error on failed move job
  • Fix missing mutex lock when managing video captions
  • Fix broken embed when the tab is loaded in the background on Firefox
  • Fix menu collapse/extend icon on RTL layout

Security Fixes

  • Security hardening addressing medium‑to‑high severity vulnerabilities in PeerTube <= 8.2.1 (details to be disclosed later).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track PeerTube

Get notified when new releases ship.

Sign up free

About PeerTube

ActivityPub-federated video streaming platform using P2P directly in your web browser

All releases →

Related context

Earlier breaking changes

  • v8.2.0 Drops iOS support for versions < 15.4
  • v8.2.0 Removes support for NodeJS 20; requires upgrade to NodeJS 22 (>=22.12)
  • v8.1.6 Restricts role assignment to administrators only.

Beta — feedback welcome: [email protected]