Skip to content

commafeed

v7.2.0 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 16d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

java rss rss-reader self-hosted web

Affected surfaces

rce_ssrf breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 11d

Version 7.2.0 removes Pocket sharing and hardens SSRF/DDoS defenses while adding feed icons and starred‑entry search.

Why it matters: Security severity 90 blocks arbitrary URL access in the image proxy and adds ULA/CGNAT blocking, directly reducing SSRF exposure; deprecation severity 70 eliminates the Pocket feature entirely.

Summary

AI summary

Removed Pocket sharing, added feed icon support, search for starred entries, and enhanced SSRF/DDoS protections.

Changes in this release

Security Critical

Prevents image proxy from accessing arbitrary URLs to avoid SSRF attacks.

Prevents image proxy from accessing arbitrary URLs to avoid SSRF attacks.

Source: llm_adapter@2026-07-15

Confidence: high

Security Critical

Strengthens SSRF protection by blocking ULA and CGNAT ranges.

Strengthens SSRF protection by blocking ULA and CGNAT ranges.

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Prevents DDOS attacks by filtering OPML files during imports.

Prevents DDOS attacks by filtering OPML files during imports.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds support for icons declared in feeds.

Adds support for icons declared in feeds.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Search now also works for starred entries.

Search now also works for starred entries.

Source: llm_adapter@2026-07-15

Confidence: high

Performance Low

Improves performance of the feed refresh engine.

Improves performance of the feed refresh engine.

Source: llm_adapter@2026-07-15

Confidence: high

Deprecation High

Removes Pocket sharing feature due to service discontinuation.

Removes Pocket sharing feature due to service discontinuation.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes proper display of error message when subscribing to a feed.

Fixes proper display of error message when subscribing to a feed.

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog
  • Add support for icons declared in feeds. This is useful for feeds exposed by RSS bridges (#2048)
  • Search now also works for starred entries (#2217)
  • The error message when subscribing to a feed is now properly displayed again
  • Small performance improvements to the feed refresh engine
  • Removed the Pocket sharing feature because the Pocket service has been discontinued
  • Prevent the image proxy feature to access any URL to avoid SSRF attacks
  • Strengthened the SSRF protection by also blocking ULA and CGNAT ranges
  • Prevent DDOS attacks by filtering OPML files during imports

Breaking Changes

  • Removed the Pocket sharing feature because the Pocket service has been discontinued

Security Fixes

  • Prevent image proxy from accessing arbitrary URLs to avoid SSRF attacks
  • Strengthened SSRF protection by blocking ULA and CGNAT ranges
  • Prevent DDOS attacks by filtering OPML files during imports

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track commafeed

Get notified when new releases ship.

Sign up free

About commafeed

Google Reader inspired self-hosted personal RSS reader.

All releases →

Related context

Beta — feedback welcome: [email protected]