Skip to content

FileRise

v3.21.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 21d File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

acl docker file-editor file-manager file-upload folder-management
+11 more
javascript multi-file-upload php self-hosted sso twofactor-auth unraid uploader web web-based webdav

Affected surfaces

auth

Summary

AI summary

Updates v3.21.0, auth, and config across a mixed release.

Full changelog

Changes 07/05/2026 (v3.21.0)

release(v3.21.0): authentication and public config hardening

Commit message

release(v3.21.0): authentication and public config hardening

- security(auth): enforce disabled login methods server-side
- security(auth): add source-wide failed-login throttling
- security(config): sanitize public footer branding HTML server-side

Fixed

  • Login method policy hardening

    • Form login, Basic Auth login, and OIDC login now enforce the configured disabled-login-method flags on the server.
    • Direct requests to disabled login endpoints now return 403 Forbidden before credential validation or OIDC flow setup.
  • Login throttling hardening

    • Login throttling now keeps the existing per-source-and-username limit and also applies a source-wide failed-attempt limit.
    • Rotating usernames from the same source no longer grants unlimited fresh login-attempt budgets.
  • Public branding config hardening

    • Public site configuration now sanitizes footer branding HTML server-side before returning it to clients.
    • Existing safe footer text, inline formatting, and safe links are preserved.

Upgrade notes

  • Deployments that intentionally disabled a login method in the Admin Panel must now re-enable it before direct API use of that method will work.
  • Deployments behind reverse proxies should verify trusted proxy/IP header settings so login throttling uses the real client IP instead of the proxy address.
  • Footer branding now permits safe text, inline formatting, and safe links; unsupported active or embedded HTML is stripped.

v3.21.0

Full Changelog

v3.20.0 → v3.21.0

SHA-256 (zip)

453fea2c671916366d9517547833a6f39bcd3f3bab7bc1f8a579b63c930d6e92  FileRise-v3.21.0.zip

Security Fixes

  • Disabled login methods now return 403 Forbidden server‑side
  • Public footer branding HTML sanitized server‑side to strip unsafe active/embedded content

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track FileRise

Get notified when new releases ship.

Sign up free

About FileRise

FileRise – lightweight, self-hosted file manager & storage hub with granular ACLs, resumable uploads, encrypted folders, WebDAV & SSO. Fully Docker / Unraid compatible.

All releases →

Related context

Beta — feedback welcome: [email protected]