Skip to content

sftpgo

v2.7.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 9d File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

azure-blob cloud-storage data-at-rest-encryption docker ftp ftp-server
+12 more
go google-cloud-storage multi-factor-authentication portable prometheus proxy-protocol s3 scp sftp sftp-server webdav webdav-server

Affected surfaces

auth

Summary

AI summary

Improper handling of malformed SSH channel requests fixed.

Full changelog

Bug fixes

  • httpd: make sure to always close connection for shares.

Security fixes

Security Fixes

  • GHSA-q7pc-356p-hggc — Improper handling of malformed SSH channel requests

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track sftpgo

Get notified when new releases ship.

Sign up free

About sftpgo

Full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob

All releases →

Related context

Beta — feedback welcome: [email protected]