This release includes 1 security fix for security teams reviewing exposed deployments.
Published 2d
File Storage & Sync
✓ No known CVEs patched
This release patches 1 known CVE
Topics
file-browser
file-manager
file-sharing
go
material-design
self-hosted
+1 more
vue
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates http, storage, and auth across a mixed release.
Full changelog
Changelog
- 328f629181888760f3c8b3ff9f3b5bec50f4e54f chore(release): 2.63.19
- 4c3cb4bc9b7a165ef42cf79f0e0842bbc42e26fd test(http): cover TUS Upload-Length enforcement
- 3213b605be4f8f9938b093a3384d404d66e7a28b test(http): cover scope-safe removal on TUS upload eviction
- 610e0b09e93e4b1940b9d50c9b0374ccab02a0d5 test(http): cover download-permission gate on the checksum branch
- 7453c78c9877cbee71dfbad06326d450102e59de test(storage): cover case-insensitive GetByScope matching
- cd5749dff8bbc2c16f99b7a127651a9d8e0da694 test(auth): cover per-user scope isolation for proxy and hook provisioning
- 4daddec6f200b03a721197d8c0b4b652c994894e fix(http): enforce declared Upload-Length on TUS uploads
- 9bd79c3aaeb4a55b0e69cf8976c4a258db2f5e06 fix(http): delete abandoned TUS uploads through the scoped filesystem
- 6c69b5cd895e15b29e563200a9a6dfc27b06525e fix(http): enforce download permission on the checksum branch
- 4b8a8d72ce554dde378b5091da74aa930ea18327 fix(storage): reject case-folded home directory collisions
- 8ddd3d1db9b9f5727d0bf96ea0e7d9a25a8692b4 fix(auth): isolate auto-provisioned proxy and hook users to their own home
- 9fffee387ff102728e47531ebc6cf5d1dd39bbf1 docs: remove go report
- 5a12cad54855b6bb3189f0d5ea93942647989ba5 docs: update readme
- 6232686e222eae9e627c8c432e3e1d6796782971 chore: update translations
- b21b1245ae1b57f031b2f5d787f32a17532402c0 fix: accessibility and security improvements (#6033)
- 7361d91ea2e8cc200a0f40ac84adcd02aedc9ed2 fix(upload): handle encoded path conflicts safely (#6040)
- c05c66814891c3cccef394162e428444b53394e4 fix: process --FollowExternalSymlinks
- b7dc392838f11d188f0bc0f2a1a99fad3f7dca03 docs: fix typo
- ac46cf06719575477d5125e7472037c204b3702d fix: return error instead of panicking on an unreadable directory during copy (#6020)
- f0785391bf11cc8ec53bff7b2f36a29a02f536dc chore: update translations (#6019)
- 9b78324d773c790951cc6a97840c4b55f66b5f3d fix(http): run upload hooks for directories (#6034)
Security Fixes
- Fix: accessibility and security improvements (#6033)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]