This release includes 5 security fixes for security teams reviewing exposed deployments.
Published 1mo
Dashboards & Home Pages
✓ No known CVEs patched
This release patches 5 known CVEs
Topics
budgeting
docker
finance
php
self-hosted
subscription-tracker
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates Bug Fixes, 4.9.6, and 2026-06-22 across a mixed release.
Full changelog
4.9.6 (2026-06-22)
Bug Fixes
- account takeover via email-based account linking (b75f13d)
- harden oidc state validation and session rotation (#1071) (b75f13d)
- missing fields when cloning a subscription (b75f13d)
- ssrf via oidc token/userInfo url configuration (b75f13d)
- ssrf via test email notification (b75f13d)
- zip slip path traversal in database restore writes files to webroot (b75f13d)
Security Fixes
- CVE‑2026‑XXXXX — fixes account takeover via email‑based account linking
- CVE‑2026‑XXXXX — hardens OIDC state validation and session rotation
- CVE‑2026‑XXXXX — prevents SSRF via OIDC token/userInfo URL configuration
- CVE‑2026‑XXXXX — prevents SSRF via test email notification
- CVE‑2026‑XXXXX — fixes ZIP‑slip path traversal in database restore (files written to webroot)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Wallos
Wallos: Open-source, self-hostable personal subscription tracker. Visualize your recurring expenses, manage your budget, and save money.
Beta — feedback welcome: [email protected]