Skip to content

convoy

v26.6.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 19d Alerting & Incidents
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

angular api-gateway automation cli cloud convoy
+12 more
developer-tools devtools gateway gateways go incoming-webhooks infrastructure outgoing-webhooks webhook-gateway webhook-service webhooks webhooks-server

Affected surfaces

auth rce_ssrf

Summary

AI summary

Redacted secrets and closed SSRF gaps across config, delivery, and notifications.

Full changelog

What's Changed

  • refactor(controlplane): require licenser via service constructors by @mekilis in https://github.com/frain-dev/convoy/pull/2705
  • fix(controlplane): redact secrets and close SSRF gaps across config, delivery, and notifications by @mekilis in https://github.com/frain-dev/convoy/pull/2706
  • fix(dataplane): capture delivery attempt timestamps around the dispatch call by @mekilis in https://github.com/frain-dev/convoy/pull/2707
  • chore(release): prepare v26.6.2 by @mekilis in https://github.com/frain-dev/convoy/pull/2708

Full Changelog: https://github.com/frain-dev/convoy/compare/v26.6.1...v26.6.2

Security Fixes

  • Redacted secrets and closed SSRF gaps across config, delivery, and notifications.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track convoy

Get notified when new releases ship.

Sign up free

About convoy

The Cloud Native Webhooks Gateway

All releases →

Related context

Beta — feedback welcome: [email protected]