Skip to content

Dispatcharr

v0.26.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Media Servers
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 2 known CVEs

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

The v0.26.0 release fixes a reflected XSS vulnerability in the M3U endpoint and updates frontend npm dependencies to resolve six audit vulnerabilities, including one critical issue.

Why it matters: Addresses a reflected XSS flaw (M3U API) and resolves 6 npm audit findingsβ€”including a critical severityβ€”requiring immediate dependency update.

Summary

AI summary

Broad release touches EPG Logo Auto-Apply, DVR Recordings, Schedules Direct EPG Integration, and πŸ”’ Security.

Changes in this release

Security Critical

Fixes reflected XSS in M3U endpoint error responses.

Fixes reflected XSS in M3U endpoint error responses.

Source: llm_adapter@2026-06-08

Confidence: high

β€”
Security Critical

Updates frontend npm dependencies to resolve 6 audit vulnerabilities (including critical).

Updates frontend npm dependencies to resolve 6 audit vulnerabilities (including critical).

Source: llm_adapter@2026-06-08

Confidence: high

β€”
Feature Medium

Adds automatic channel logo application from EPG data for XMLTV and Schedules Direct sources.

Adds automatic channel logo application from EPG data for XMLTV and Schedules Direct sources.

Source: llm_adapter@2026-06-08

Confidence: high

β€”
Feature Medium

Adds sticky pagination footer with configurable page size in Plugin Browse.

Adds sticky pagination footer with configurable page size in Plugin Browse.

Source: llm_adapter@2026-06-08

Confidence: high

β€”
Feature Medium

Adds Schedules Direct EPG integration with credential login and lineup manager.

Adds Schedules Direct EPG integration with credential login and lineup manager.

Source: llm_adapter@2026-06-08

Confidence: low

β€”
Feature Medium

Adds live EPG program preview in channel editor UI.

Adds live EPG program preview in channel editor UI.

Source: llm_adapter@2026-06-08

Confidence: low

β€”
Feature Medium

Adds privacy‑friendly public IP blurring in sidebar with toggle and env override.

Adds privacy‑friendly public IP blurring in sidebar with toggle and env override.

Source: llm_adapter@2026-06-08

Confidence: low

β€”
Feature Low

Adds Schedules Direct EPG integration with credential login, lineup manager, delta downloads, logo variants, optional poster fetch, cast info, and stations‑only initial fetch.

Adds Schedules Direct EPG integration with credential login, lineup manager, delta downloads, logo variants, optional poster fetch, cast info, and stations‑only initial fetch.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Feature Low

Shows live EPG program preview (title, description, progress bar) in channel editor UI; reused on Stats page.

Shows live EPG program preview (title, description, progress bar) in channel editor UI; reused on Stats page.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Feature Low

Blurs public IP by default in sidebar; reveals on click, with Settings toggle and `DISPATCHARR_ENABLE_IP_LOOKUP` env override.

Blurs public IP by default in sidebar; reveals on click, with Settings toggle and `DISPATCHARR_ENABLE_IP_LOOKUP` env override.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Feature Low

Captures director, cast, release date, and trailer during initial VOD sync without needing an advanced refresh.

Captures director, cast, release date, and trailer during initial VOD sync without needing an advanced refresh.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Dependency Low

Upgrades database driver to psycopg3 and uses persistent per‑worker connection pools.

Upgrades database driver to psycopg3 and uses persistent per‑worker connection pools.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Performance Medium

Improves `get_vod_streams` and `get_series` XC API response times for large libraries (e.g., 18s β†’ 12s, 9.5s β†’ 3.5s).

Improves `get_vod_streams` and `get_series` XC API response times for large libraries (e.g., 18s β†’ 12s, 9.5s β†’ 3.5s).

Source: llm_adapter@2026-06-08

Confidence: high

β€”
Performance Medium

Optimizes M3U and EPG logo URL generation for large playlists; caches logo/poster data on persistent `/data` volume; reduces Stats page round‑trips and duplicate fetches.

Optimizes M3U and EPG logo URL generation for large playlists; caches logo/poster data on persistent `/data` volume; reduces Stats page round‑trips and duplicate fetches.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix High

Fixes DVR recordings stopping mid‑stream and restarting correctly.

Fixes DVR recordings stopping mid‑stream and restarting correctly.

Source: llm_adapter@2026-06-08

Confidence: low

β€”
Bugfix Medium

Fixes null keepalive packets causing Emby/Jellyfin playback failures.

Fixes null keepalive packets causing Emby/Jellyfin playback failures.

Source: llm_adapter@2026-06-08

Confidence: high

β€”
Bugfix Medium

Fixes DVR recordings that stop mid‑stream, restarting and concatenating segments into a continuous file.

Fixes DVR recordings that stop mid‑stream, restarting and concatenating segments into a continuous file.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Medium

Fixes VOD proxy stream URLs breaking after M3U import refresh via fallback ID resolution.

Fixes VOD proxy stream URLs breaking after M3U import refresh via fallback ID resolution.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Medium

Ensures per‑channel stream profile overrides are applied during live and VOD streaming across all UI components.

Ensures per‑channel stream profile overrides are applied during live and VOD streaming across all UI components.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Medium

Correctly identifies authenticated users in VOD connection cards and web‑player events.

Correctly identifies authenticated users in VOD connection cards and web‑player events.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Medium

Refreshes EPG channel list after source parsing completes, fixing empty picker/UI issues.

Refreshes EPG channel list after source parsing completes, fixing empty picker/UI issues.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Medium

Prevents UI crash when deleting the last playlist; gracefully handles deletion.

Prevents UI crash when deleting the last playlist; gracefully handles deletion.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Medium

Resolves Channel Group Override issues: compact numbering failure, missing reset button, and unnecessary repacking on unchanged syncs.

Resolves Channel Group Override issues: compact numbering failure, missing reset button, and unnecessary repacking on unchanged syncs.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Low

Includes non‑standard ports in HDHomeRun lineup, discovery, and device URLs behind reverse proxies.

Includes non‑standard ports in HDHomeRun lineup, discovery, and device URLs behind reverse proxies.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Low

Makes provider selection in VOD/Series detail modal affect displayed data correctly.

Makes provider selection in VOD/Series detail modal affect displayed data correctly.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Low

Fixes truncation of cast and actor lists to only first name when provider returns full list.

Fixes truncation of cast and actor lists to only first name when provider returns full list.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Bugfix Low

Runs database migrations automatically after restoring older backups to avoid schema errors.

Runs database migrations automatically after restoring older backups to avoid schema errors.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Refactor Low

Deploys Dispatcharr under uWSGI with gevent workers for Debian/LXC installs, matching Docker stack.

Deploys Dispatcharr under uWSGI with gevent workers for Debian/LXC installs, matching Docker stack.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Refactor Low

Adopts multi‑stage Docker builds, reducing image size by shipping only runtime libraries.

Adopts multi‑stage Docker builds, reducing image size by shipping only runtime libraries.

Source: granite4.1:30b@2026-06-08-audit

Confidence: low

β€”
Full changelog

✨ New Features

Schedules Direct EPG Integration

  • Dispatcharr is now an approved Schedules Direct application, with native EPG support alongside XMLTV and dummy EPG. Existing Schedules Direct subscribers can connect with their account credentials. (Closes #1246) - Thanks @Shokkstokk:
    • Credential-based login, lineup management, and guide refresh through the existing EPG pipeline
    • A lineup manager in EPG source settings lets you search by postal code and add or remove up to four active lineups. The UI surfaces Schedules Direct's six-adds-per-24-hours limit and when the counter resets at midnight UTC.
    • Guide refreshes use delta downloads to skip unchanged schedule and program data when possible. A two-hour minimum interval between full refreshes is enforced (bypassable via force refresh).
    • Station logos can be fetched in dark, light, gray, or white variants and stored alongside XMLTV channel icons.
    • Optional program poster fetch (off by default) with configurable style preferences, served through a backend proxy that caches images on first view.
    • Cast information in the XMLTV output now includes character names and guest stars in a format compatible with common media servers.
    • A lightweight stations-only fetch runs when a new source is created so EPG entries exist for auto-matching before the first full schedule pull.

EPG Logo Auto-Apply

  • Channel logos can now be applied automatically from EPG data for both XMLTV and Schedules Direct sources.
  • The existing "Set Logos from EPG" bulk action, per-source auto-apply on refresh setting, and the set-logos API all share the same logic, so behavior is consistent regardless of how you trigger it.
  • Large channel libraries are processed in manageable chunks so logo assignment stays responsive even with thousands of mapped channels.

Live EPG Program Preview in Channel Editor

  • A "Current Program" preview now appears when you select an EPG channel in the channel create/edit form. - Thanks @FiveBoroughs:
    • Shows the currently airing program title, description, and a progress bar
    • Lookups return results almost instantly regardless of EPG source size. If the index has not yet been built for a source, the UI automatically retries in the background until data is available.
    • The same preview component is now reused on the Stats page for a consistent experience.

Public IP Privacy in Sidebar

  • Public IP display in the sidebar is now more privacy-friendly. (Closes #1302) - Thanks @sethwv:
    • The public IP address is blurred by default and reveals only when you click it, reducing accidental exposure in screenshots and screen shares
    • A new toggle in Settings β†’ System Settings lets you disable IP and geolocation fetching entirely
    • A DISPATCHARR_ENABLE_IP_LOOKUP environment variable provides a container-level override; when set to false, the toggle is hidden and cannot be changed

Plugin Browse Pagination

  • Plugin Browse now has a sticky pagination footer and configurable page size. - Thanks @sethwv:
    • Pagination controls sit in a fixed footer bar at the bottom of the page, with a page-size selector (9 / 18 / 27 / 36) and an item range readout (X to Y of Z)
    • Your selected page size is remembered across visits

VOD Metadata from Basic Sync

  • When a provider includes director, cast, release_date, or trailer information in its stream list, Dispatcharr now captures and stores those fields during the initial VOD sync pass instead of requiring a separate advanced refresh. - Thanks @nemesbak

πŸ”„ Changes & Improvements

Channel Edit Form

  • The channel create/edit form has been reorganized into three columns: Identity (name, number, group, logo), Guide Data (TVG-ID, Gracenote StationId, EPG picker, current program preview), and Behavior/Access (stream profile, user level, mature content, hidden). The wider Guide Data column gives the program preview enough room to display long titles correctly.

IP Lookup

  • When the background IP lookup completes, the sidebar IP field updates automatically via a real-time push β€” no polling required. A loading placeholder is shown while the lookup is in progress.
  • The settings page no longer blocks while waiting for external IP lookup services. Lookups run in the background on first request and results are cached for one hour. - Thanks @sethwv

Schedules Direct

  • The EPG source delete confirmation dialog for Schedules Direct sources now shows only the username, not password or API key fields.

VOD XC API Output

  • The get_vod_streams XC API endpoint now includes director, cast, release_date, plot, genre, and year when those fields were captured during basic sync. The trailer field now correctly maps to stored YouTube trailer data. Users with existing libraries should trigger a VOD provider refresh to populate any missing fields. (Fixes #1228)

Logo & Poster Caching

  • Logo and poster proxy cache data is now stored on the persistent /data volume instead of inside the application directory, so cached images survive container updates.
  • Logo cache URLs now correctly include non-standard ports when Dispatcharr is accessed behind a reverse proxy or on a custom port, matching the behavior already applied to M3U and EPG URLs.

Debian / LXC Bare-Metal Install

  • The Debian/LXC installer now deploys Dispatcharr under uWSGI with gevent workers, matching the Docker deployment stack and eliminating compatibility differences between install paths.
  • M3U playlist URLs on bare-metal installs now correctly include the configured port number behind reverse proxies. Python 3.13 is provisioned through uv's managed runtime so the installer works on Debian 12 and Ubuntu 24.04 LTS regardless of the system Python version.

Docker Image

  • The Docker image now uses a multi-stage build that compiles dependencies in a builder stage and ships only runtime libraries in the final image, reducing image size and removing compiler tools from production containers. - Thanks @kensac

Database

  • The database driver has been upgraded to psycopg3, which cooperates with gevent's cooperative multitasking without additional patching.
  • Database connections are now managed by a persistent per-worker pool, eliminating the overhead of opening a fresh connection on every request. - Thanks @JCBird1012

Performance

  • M3U and EPG channel logo URLs are built more efficiently for large playlists, with the base URL computed once per request instead of per channel.
  • get_vod_streams and get_series XC API responses are significantly faster for large libraries. Both endpoints now return exactly one row per title (respecting account priority) and sort results alphabetically. Observed improvements include 18s β†’ 12s for ~48k movies and 9.5s β†’ 3.5s for ~11k series.
  • The Stats page channel status endpoint makes fewer backend round-trips when many streams are active, reducing the chance of timeouts on other pages during heavy load. The Stats page also no longer fires a duplicate initial fetch on load. - Thanks @JCBird1012
  • EPG refresh progress updates (including Schedules Direct) are now delivered reliably to connected browsers during background refreshes.

Plugin Repository

  • Several Plugin Browse and repository improvements. - Thanks @sethwv:
    • The default official plugin repository URL now points to GitHub Pages instead of a raw GitHub content URL, avoiding stale cached manifests. Existing official repository entries are updated automatically.
    • Plugins with available updates now sort to the top of the list so pending updates are easy to spot.
    • The disabled state on size-labeled install buttons now renders with a clearer grayed-out appearance.

Frontend Testing

  • Unit test coverage has been extended to additional form components and the Guide page, with business logic extracted into testable utility modules. - Thanks @nick4810

πŸ› Bug Fixes

DVR Recordings

  • Fixed DVR recordings stopping immediately when the recording process exits mid-stream. If the source drops or the recorder crashes before the scheduled end time, Dispatcharr now restarts recording in-process and continues segment numbering so the final file is a single continuous recording. Retries are bounded by a configurable outage window; if recovery fails, the recording is saved as interrupted rather than falsely marked complete. (Closes #1170)
  • Fixed the finalize step failing on recordings that had timestamp gaps or corrupt segments from mid-recording restarts. Concatenation now tolerates minor corruption and timestamp discontinuities.
  • Fixed segment numbering skipping ahead after a mid-recording restart, which could leave gaps in the output file.

Streaming & Media Server Compatibility

  • Fixed null keepalive packets during channel initialization causing Emby and Jellyfin to force a deinterlace transcode or fail playback entirely. (Fixes #1280)
  • Fixed VOD proxy stream URLs breaking after an M3U import refresh when external players (Emby, Jellyfin, Channels DVR) had cached .strm URLs. The proxy now falls back to stream ID resolution when a cached UUID no longer matches. - Thanks @R3XCHRIS
  • Fixed per-channel stream profile overrides being ignored during streaming. Channels with an override set on auto-synced channels now correctly use the overridden profile. (Fixes #1268) - Thanks @nemesbak
  • Fixed the web-player output profile being ignored when starting live streams from the TV Guide, Program Detail modal, DVR page, or Recording Details β€” only the Channels page was applying the profile correctly. (Fixes #1304) - Thanks @nemesbak
  • Fixed authenticated users not being identified in VOD connection cards and stream events when streaming via the built-in web player. (Fixes #1224)

HDHomeRun

  • Fixed HDHomeRun lineup, discovery, and device URLs dropping non-standard ports behind reverse proxies and on development installs. These URLs now include the correct port, matching M3U, EPG, and XC output.

EPG

  • Fixed the EPG channel list not refreshing after a source finished parsing channels. The channel picker and EPG assignment UI stayed empty until a full page reload.

VOD & Playlists

  • Fixed switching providers in the VOD or Series detail modal having no effect β€” data always came from the highest-priority provider regardless of the dropdown selection. (Fixes #1285) - Thanks @nemesbak
  • Fixed deleting the last playlist (or any playlist) crashing the entire UI with an error screen. (Fixes #1269) - Thanks @nemesbak
  • Fixed cast and actor lists being silently truncated to only the first name when a provider returned them as a list.

Auto-Sync & Channel Numbering

  • Fixed several issues with Channel Group Overrides and compact numbering. - Thanks @CodeBormen:
    • Compact numbering silently failed when a Channel Group Override was in use β€” hide, unhide, and repack operations could miss channels stored under the override target group. (Fixes #1263, Fixes #1276)
    • The clear-override reset button disappeared when an override's value happened to match the provider value. The reset button now appears whenever any override row exists.
    • Auto-synced channel numbers reshuffled on every sync even when the provider returned no changes. Compact repack now uses a stable sort order so channel numbers stay put unless the provider data actually changes. (Fixes #1321)

Backups

  • Fixed restoring a backup from an older version leaving the database with a missing schema. Migrations now run automatically after every restore, and the success notification recommends a restart to clear stale service state.

πŸ”’ Security

  • Fixed the M3U endpoint reflecting POST body content in error responses, which could be exploited for reflected cross-site scripting. - Thanks @sebastiondev
  • Updated frontend npm dependencies to resolve 5 audit vulnerabilities (2 moderate, 2 high, 1 critical):

Security Fixes

  • M3U endpoint no longer reflects POST body content, fixing reflected XSS (GHSA-49rj-9fvp-4h2h).
  • Frontend npm dependencies updated: react‑router/react‑router‑domβ€―7.13.0β†’7.17.0 (multiple high/critical CVEs), vitestβ€―3.2.4β†’4.1.8 (critical file read/exec, GHSA-5xrq-8626-4rwp), brace-expansionβ€―5.0.5β†’5.0.6 (moderate DoS, GHSA-jxxr-4gwj-5jf2), wsβ€―8.19.0β†’8.21.0 (moderate uninitialized memory disclosure, GHSA-58qx-3vcg-4xpx).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Dispatcharr

Get notified when new releases ship.

Sign up free

About Dispatcharr

Open-source IPTV stream management platform for consolidating multiple providers, managing EPG data, and sharing content with advanced control features

All releases β†’

Related context

Beta — feedback welcome: [email protected]