Skip to content

cypht

v2.11.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

atom e-mail ews imap jmap news-reader
+6 more
php pop3 rss smtp webmail webmail-client

Affected surfaces

rce_ssrf

Summary

AI summary

Block SSRF to private and internal feed URLs

Full changelog

Security fixes only

  • fix(module/feeds): block SSRF to private and internal feed URLs by @IrAlfred in #2024

We greatly appreciate Sanjorn Keeratirungsan (HackerOne) for identifying and reporting the security concerns addressed in this release. Thank you for your collaboration and commitment!

Full Changelog: https://github.com/cypht-org/cypht/compare/v2.11.1...v2.11.2

Security Fixes

  • fix(module/feeds): block SSRF to private and internal feed URLs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track cypht

Get notified when new releases ship.

Sign up free

About cypht

Cypht: Lightweight Open Source webmail aggregator [PHP, JS]. Supports IMAP/SMTP, JMAP and EWS (Exchange Web Services)

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]