This release includes 2 security fixes for security teams reviewing exposed deployments.
Affected surfaces
ReleasePort's take
Moderate signalThe v0.26.0 release fixes a reflected XSS vulnerability in the M3U endpoint and updates frontend npm dependencies to resolve six audit vulnerabilities, including one critical issue.
Why it matters: Addresses a reflected XSS flaw (M3U API) and resolves 6 npm audit findingsβincluding a critical severityβrequiring immediate dependency update.
Summary
AI summaryBroad release touches EPG Logo Auto-Apply, DVR Recordings, Schedules Direct EPG Integration, and π Security.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes reflected XSS in M3U endpoint error responses. Fixes reflected XSS in M3U endpoint error responses. Source: llm_adapter@2026-06-08 Confidence: high |
β |
| Security | Critical |
Updates frontend npm dependencies to resolve 6 audit vulnerabilities (including critical). Updates frontend npm dependencies to resolve 6 audit vulnerabilities (including critical). Source: llm_adapter@2026-06-08 Confidence: high |
β |
| Feature | Medium |
Adds automatic channel logo application from EPG data for XMLTV and Schedules Direct sources. Adds automatic channel logo application from EPG data for XMLTV and Schedules Direct sources. Source: llm_adapter@2026-06-08 Confidence: high |
β |
| Feature | Medium |
Adds sticky pagination footer with configurable page size in Plugin Browse. Adds sticky pagination footer with configurable page size in Plugin Browse. Source: llm_adapter@2026-06-08 Confidence: high |
β |
| Feature | Medium |
Adds Schedules Direct EPG integration with credential login and lineup manager. Adds Schedules Direct EPG integration with credential login and lineup manager. Source: llm_adapter@2026-06-08 Confidence: low |
β |
| Feature | Medium |
Adds live EPG program preview in channel editor UI. Adds live EPG program preview in channel editor UI. Source: llm_adapter@2026-06-08 Confidence: low |
β |
| Feature | Medium |
Adds privacyβfriendly public IP blurring in sidebar with toggle and env override. Adds privacyβfriendly public IP blurring in sidebar with toggle and env override. Source: llm_adapter@2026-06-08 Confidence: low |
β |
| Feature | Low |
Adds Schedules Direct EPG integration with credential login, lineup manager, delta downloads, logo variants, optional poster fetch, cast info, and stationsβonly initial fetch. Adds Schedules Direct EPG integration with credential login, lineup manager, delta downloads, logo variants, optional poster fetch, cast info, and stationsβonly initial fetch. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Feature | Low |
Shows live EPG program preview (title, description, progress bar) in channel editor UI; reused on Stats page. Shows live EPG program preview (title, description, progress bar) in channel editor UI; reused on Stats page. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Feature | Low |
Blurs public IP by default in sidebar; reveals on click, with Settings toggle and `DISPATCHARR_ENABLE_IP_LOOKUP` env override. Blurs public IP by default in sidebar; reveals on click, with Settings toggle and `DISPATCHARR_ENABLE_IP_LOOKUP` env override. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Feature | Low |
Captures director, cast, release date, and trailer during initial VOD sync without needing an advanced refresh. Captures director, cast, release date, and trailer during initial VOD sync without needing an advanced refresh. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Dependency | Low |
Upgrades database driver to psycopg3 and uses persistent perβworker connection pools. Upgrades database driver to psycopg3 and uses persistent perβworker connection pools. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Performance | Medium |
Improves `get_vod_streams` and `get_series` XC API response times for large libraries (e.g., 18s β 12s, 9.5s β 3.5s). Improves `get_vod_streams` and `get_series` XC API response times for large libraries (e.g., 18s β 12s, 9.5s β 3.5s). Source: llm_adapter@2026-06-08 Confidence: high |
β |
| Performance | Medium |
Optimizes M3U and EPG logo URL generation for large playlists; caches logo/poster data on persistent `/data` volume; reduces Stats page roundβtrips and duplicate fetches. Optimizes M3U and EPG logo URL generation for large playlists; caches logo/poster data on persistent `/data` volume; reduces Stats page roundβtrips and duplicate fetches. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | High |
Fixes DVR recordings stopping midβstream and restarting correctly. Fixes DVR recordings stopping midβstream and restarting correctly. Source: llm_adapter@2026-06-08 Confidence: low |
β |
| Bugfix | Medium |
Fixes null keepalive packets causing Emby/Jellyfin playback failures. Fixes null keepalive packets causing Emby/Jellyfin playback failures. Source: llm_adapter@2026-06-08 Confidence: high |
β |
| Bugfix | Medium |
Fixes DVR recordings that stop midβstream, restarting and concatenating segments into a continuous file. Fixes DVR recordings that stop midβstream, restarting and concatenating segments into a continuous file. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Medium |
Fixes VOD proxy stream URLs breaking after M3U import refresh via fallback ID resolution. Fixes VOD proxy stream URLs breaking after M3U import refresh via fallback ID resolution. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Medium |
Ensures perβchannel stream profile overrides are applied during live and VOD streaming across all UI components. Ensures perβchannel stream profile overrides are applied during live and VOD streaming across all UI components. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Medium |
Correctly identifies authenticated users in VOD connection cards and webβplayer events. Correctly identifies authenticated users in VOD connection cards and webβplayer events. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Medium |
Refreshes EPG channel list after source parsing completes, fixing empty picker/UI issues. Refreshes EPG channel list after source parsing completes, fixing empty picker/UI issues. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Medium |
Prevents UI crash when deleting the last playlist; gracefully handles deletion. Prevents UI crash when deleting the last playlist; gracefully handles deletion. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Medium |
Resolves Channel Group Override issues: compact numbering failure, missing reset button, and unnecessary repacking on unchanged syncs. Resolves Channel Group Override issues: compact numbering failure, missing reset button, and unnecessary repacking on unchanged syncs. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Low |
Includes nonβstandard ports in HDHomeRun lineup, discovery, and device URLs behind reverse proxies. Includes nonβstandard ports in HDHomeRun lineup, discovery, and device URLs behind reverse proxies. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Low |
Makes provider selection in VOD/Series detail modal affect displayed data correctly. Makes provider selection in VOD/Series detail modal affect displayed data correctly. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Low |
Fixes truncation of cast and actor lists to only first name when provider returns full list. Fixes truncation of cast and actor lists to only first name when provider returns full list. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Bugfix | Low |
Runs database migrations automatically after restoring older backups to avoid schema errors. Runs database migrations automatically after restoring older backups to avoid schema errors. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Refactor | Low |
Deploys Dispatcharr under uWSGI with gevent workers for Debian/LXC installs, matching Docker stack. Deploys Dispatcharr under uWSGI with gevent workers for Debian/LXC installs, matching Docker stack. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
| Refactor | Low |
Adopts multiβstage Docker builds, reducing image size by shipping only runtime libraries. Adopts multiβstage Docker builds, reducing image size by shipping only runtime libraries. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
β |
Full changelog
β¨ New Features
Schedules Direct EPG Integration
- Dispatcharr is now an approved Schedules Direct application, with native EPG support alongside XMLTV and dummy EPG. Existing Schedules Direct subscribers can connect with their account credentials. (Closes #1246) - Thanks @Shokkstokk:
- Credential-based login, lineup management, and guide refresh through the existing EPG pipeline
- A lineup manager in EPG source settings lets you search by postal code and add or remove up to four active lineups. The UI surfaces Schedules Direct's six-adds-per-24-hours limit and when the counter resets at midnight UTC.
- Guide refreshes use delta downloads to skip unchanged schedule and program data when possible. A two-hour minimum interval between full refreshes is enforced (bypassable via force refresh).
- Station logos can be fetched in dark, light, gray, or white variants and stored alongside XMLTV channel icons.
- Optional program poster fetch (off by default) with configurable style preferences, served through a backend proxy that caches images on first view.
- Cast information in the XMLTV output now includes character names and guest stars in a format compatible with common media servers.
- A lightweight stations-only fetch runs when a new source is created so EPG entries exist for auto-matching before the first full schedule pull.
EPG Logo Auto-Apply
- Channel logos can now be applied automatically from EPG data for both XMLTV and Schedules Direct sources.
- The existing "Set Logos from EPG" bulk action, per-source auto-apply on refresh setting, and the set-logos API all share the same logic, so behavior is consistent regardless of how you trigger it.
- Large channel libraries are processed in manageable chunks so logo assignment stays responsive even with thousands of mapped channels.
Live EPG Program Preview in Channel Editor
- A "Current Program" preview now appears when you select an EPG channel in the channel create/edit form. - Thanks @FiveBoroughs:
- Shows the currently airing program title, description, and a progress bar
- Lookups return results almost instantly regardless of EPG source size. If the index has not yet been built for a source, the UI automatically retries in the background until data is available.
- The same preview component is now reused on the Stats page for a consistent experience.
Public IP Privacy in Sidebar
- Public IP display in the sidebar is now more privacy-friendly. (Closes #1302) - Thanks @sethwv:
- The public IP address is blurred by default and reveals only when you click it, reducing accidental exposure in screenshots and screen shares
- A new toggle in Settings β System Settings lets you disable IP and geolocation fetching entirely
- A
DISPATCHARR_ENABLE_IP_LOOKUPenvironment variable provides a container-level override; when set tofalse, the toggle is hidden and cannot be changed
Plugin Browse Pagination
- Plugin Browse now has a sticky pagination footer and configurable page size. - Thanks @sethwv:
- Pagination controls sit in a fixed footer bar at the bottom of the page, with a page-size selector (9 / 18 / 27 / 36) and an item range readout (
X to Y of Z) - Your selected page size is remembered across visits
- Pagination controls sit in a fixed footer bar at the bottom of the page, with a page-size selector (9 / 18 / 27 / 36) and an item range readout (
VOD Metadata from Basic Sync
- When a provider includes
director,cast,release_date, or trailer information in its stream list, Dispatcharr now captures and stores those fields during the initial VOD sync pass instead of requiring a separate advanced refresh. - Thanks @nemesbak
π Changes & Improvements
Channel Edit Form
- The channel create/edit form has been reorganized into three columns: Identity (name, number, group, logo), Guide Data (TVG-ID, Gracenote StationId, EPG picker, current program preview), and Behavior/Access (stream profile, user level, mature content, hidden). The wider Guide Data column gives the program preview enough room to display long titles correctly.
IP Lookup
- When the background IP lookup completes, the sidebar IP field updates automatically via a real-time push β no polling required. A loading placeholder is shown while the lookup is in progress.
- The settings page no longer blocks while waiting for external IP lookup services. Lookups run in the background on first request and results are cached for one hour. - Thanks @sethwv
Schedules Direct
- The EPG source delete confirmation dialog for Schedules Direct sources now shows only the username, not password or API key fields.
VOD XC API Output
- The
get_vod_streamsXC API endpoint now includesdirector,cast,release_date,plot,genre, andyearwhen those fields were captured during basic sync. The trailer field now correctly maps to stored YouTube trailer data. Users with existing libraries should trigger a VOD provider refresh to populate any missing fields. (Fixes #1228)
Logo & Poster Caching
- Logo and poster proxy cache data is now stored on the persistent
/datavolume instead of inside the application directory, so cached images survive container updates. - Logo cache URLs now correctly include non-standard ports when Dispatcharr is accessed behind a reverse proxy or on a custom port, matching the behavior already applied to M3U and EPG URLs.
Debian / LXC Bare-Metal Install
- The Debian/LXC installer now deploys Dispatcharr under uWSGI with gevent workers, matching the Docker deployment stack and eliminating compatibility differences between install paths.
- M3U playlist URLs on bare-metal installs now correctly include the configured port number behind reverse proxies. Python 3.13 is provisioned through uv's managed runtime so the installer works on Debian 12 and Ubuntu 24.04 LTS regardless of the system Python version.
Docker Image
- The Docker image now uses a multi-stage build that compiles dependencies in a builder stage and ships only runtime libraries in the final image, reducing image size and removing compiler tools from production containers. - Thanks @kensac
Database
- The database driver has been upgraded to psycopg3, which cooperates with gevent's cooperative multitasking without additional patching.
- Database connections are now managed by a persistent per-worker pool, eliminating the overhead of opening a fresh connection on every request. - Thanks @JCBird1012
Performance
- M3U and EPG channel logo URLs are built more efficiently for large playlists, with the base URL computed once per request instead of per channel.
get_vod_streamsandget_seriesXC API responses are significantly faster for large libraries. Both endpoints now return exactly one row per title (respecting account priority) and sort results alphabetically. Observed improvements include 18s β 12s for ~48k movies and 9.5s β 3.5s for ~11k series.- The Stats page channel status endpoint makes fewer backend round-trips when many streams are active, reducing the chance of timeouts on other pages during heavy load. The Stats page also no longer fires a duplicate initial fetch on load. - Thanks @JCBird1012
- EPG refresh progress updates (including Schedules Direct) are now delivered reliably to connected browsers during background refreshes.
Plugin Repository
- Several Plugin Browse and repository improvements. - Thanks @sethwv:
- The default official plugin repository URL now points to GitHub Pages instead of a raw GitHub content URL, avoiding stale cached manifests. Existing official repository entries are updated automatically.
- Plugins with available updates now sort to the top of the list so pending updates are easy to spot.
- The disabled state on size-labeled install buttons now renders with a clearer grayed-out appearance.
Frontend Testing
- Unit test coverage has been extended to additional form components and the Guide page, with business logic extracted into testable utility modules. - Thanks @nick4810
π Bug Fixes
DVR Recordings
- Fixed DVR recordings stopping immediately when the recording process exits mid-stream. If the source drops or the recorder crashes before the scheduled end time, Dispatcharr now restarts recording in-process and continues segment numbering so the final file is a single continuous recording. Retries are bounded by a configurable outage window; if recovery fails, the recording is saved as interrupted rather than falsely marked complete. (Closes #1170)
- Fixed the finalize step failing on recordings that had timestamp gaps or corrupt segments from mid-recording restarts. Concatenation now tolerates minor corruption and timestamp discontinuities.
- Fixed segment numbering skipping ahead after a mid-recording restart, which could leave gaps in the output file.
Streaming & Media Server Compatibility
- Fixed null keepalive packets during channel initialization causing Emby and Jellyfin to force a deinterlace transcode or fail playback entirely. (Fixes #1280)
- Fixed VOD proxy stream URLs breaking after an M3U import refresh when external players (Emby, Jellyfin, Channels DVR) had cached
.strmURLs. The proxy now falls back to stream ID resolution when a cached UUID no longer matches. - Thanks @R3XCHRIS - Fixed per-channel stream profile overrides being ignored during streaming. Channels with an override set on auto-synced channels now correctly use the overridden profile. (Fixes #1268) - Thanks @nemesbak
- Fixed the web-player output profile being ignored when starting live streams from the TV Guide, Program Detail modal, DVR page, or Recording Details β only the Channels page was applying the profile correctly. (Fixes #1304) - Thanks @nemesbak
- Fixed authenticated users not being identified in VOD connection cards and stream events when streaming via the built-in web player. (Fixes #1224)
HDHomeRun
- Fixed HDHomeRun lineup, discovery, and device URLs dropping non-standard ports behind reverse proxies and on development installs. These URLs now include the correct port, matching M3U, EPG, and XC output.
EPG
- Fixed the EPG channel list not refreshing after a source finished parsing channels. The channel picker and EPG assignment UI stayed empty until a full page reload.
VOD & Playlists
- Fixed switching providers in the VOD or Series detail modal having no effect β data always came from the highest-priority provider regardless of the dropdown selection. (Fixes #1285) - Thanks @nemesbak
- Fixed deleting the last playlist (or any playlist) crashing the entire UI with an error screen. (Fixes #1269) - Thanks @nemesbak
- Fixed cast and actor lists being silently truncated to only the first name when a provider returned them as a list.
Auto-Sync & Channel Numbering
- Fixed several issues with Channel Group Overrides and compact numbering. - Thanks @CodeBormen:
- Compact numbering silently failed when a Channel Group Override was in use β hide, unhide, and repack operations could miss channels stored under the override target group. (Fixes #1263, Fixes #1276)
- The clear-override reset button disappeared when an override's value happened to match the provider value. The reset button now appears whenever any override row exists.
- Auto-synced channel numbers reshuffled on every sync even when the provider returned no changes. Compact repack now uses a stable sort order so channel numbers stay put unless the provider data actually changes. (Fixes #1321)
Backups
- Fixed restoring a backup from an older version leaving the database with a missing schema. Migrations now run automatically after every restore, and the success notification recommends a restart to clear stale service state.
π Security
- Fixed the M3U endpoint reflecting POST body content in error responses, which could be exploited for reflected cross-site scripting. - Thanks @sebastiondev
- Updated frontend npm dependencies to resolve 5 audit vulnerabilities (2 moderate, 2 high, 1 critical):
- Updated
react-routerandreact-router-dom7.13.0 β 7.17.0, resolving high severity issues including unauthenticated remote code execution, open redirect, cross-site scripting in redirect handling, and denial-of-service vulnerabilities (GHSA-49rj-9fvp-4h2h, GHSA-2j2x-hqr9-3h42, GHSA-8646-j5j9-6r62, GHSA-f22v-gfqf-p8f3, GHSA-8x6r-g9mw-2r78, GHSA-rxv8-25v2-qmq8) - Updated
vitest3.2.4 β 4.1.8, resolving a critical arbitrary file read and execution vulnerability when the Vitest UI server is listening (GHSA-5xrq-8626-4rwp) - Updated
brace-expansion5.0.5 β 5.0.6, resolving a moderate denial-of-service vulnerability (GHSA-jxxr-4gwj-5jf2) - Updated
ws8.19.0 β 8.21.0, resolving a moderate uninitialized memory disclosure (GHSA-58qx-3vcg-4xpx)
- Updated
Security Fixes
- M3U endpoint no longer reflects POST body content, fixing reflected XSS (GHSA-49rj-9fvp-4h2h).
- Frontend npm dependencies updated: reactβrouter/reactβrouterβdomβ―7.13.0β7.17.0 (multiple high/critical CVEs), vitestβ―3.2.4β4.1.8 (critical file read/exec, GHSA-5xrq-8626-4rwp), brace-expansionβ―5.0.5β5.0.6 (moderate DoS, GHSA-jxxr-4gwj-5jf2), wsβ―8.19.0β8.21.0 (moderate uninitialized memory disclosure, GHSA-58qx-3vcg-4xpx).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Dispatcharr
Open-source IPTV stream management platform for consolidating multiple providers, managing EPG data, and sharing content with advanced control features
Related context
Related tools
Beta — feedback welcome: [email protected]