Skip to content

Wallos

v4.9.6 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

budgeting docker finance php self-hosted subscription-tracker

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates Bug Fixes, 4.9.6, and 2026-06-22 across a mixed release.

Full changelog

4.9.6 (2026-06-22)

Bug Fixes

  • account takeover via email-based account linking (b75f13d)
  • harden oidc state validation and session rotation (#1071) (b75f13d)
  • missing fields when cloning a subscription (b75f13d)
  • ssrf via oidc token/userInfo url configuration (b75f13d)
  • ssrf via test email notification (b75f13d)
  • zip slip path traversal in database restore writes files to webroot (b75f13d)

Security Fixes

  • CVE‑2026‑XXXXX — fixes account takeover via email‑based account linking
  • CVE‑2026‑XXXXX — hardens OIDC state validation and session rotation
  • CVE‑2026‑XXXXX — prevents SSRF via OIDC token/userInfo URL configuration
  • CVE‑2026‑XXXXX — prevents SSRF via test email notification
  • CVE‑2026‑XXXXX — fixes ZIP‑slip path traversal in database restore (files written to webroot)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Wallos

Get notified when new releases ship.

Sign up free

About Wallos

Wallos: Open-source, self-hostable personal subscription tracker. Visualize your recurring expenses, manage your budget, and save money.

All releases →

Related context

Earlier breaking changes

  • v5.0.0 complete ui overhaul changes application layout and interaction patterns
  • v4.9.4 Container fails to start in release 4.9.4

Beta — feedback welcome: [email protected]