This release includes 1 security fix for security teams reviewing exposed deployments.
Published 20h
Secrets & Credentials
✓ No known CVEs patched
This release patches 1 known CVE
Topics
accessibility
angular
anonymity
anticorruption
bootstrap
debian
+13 more
digital-human-rights
digital-public-goods
dompurify
free-software
libsodium
privacy
python
security
sqlalchemy
tor
twisted
typescript
whistleblowing
Affected surfaces
auth
rbac
Summary
AI summarySecurity enhancements include session‑scoped OTP cooldowns and usage alerts before billing caps.
Full changelog
Changes in version 5.0.99
- Implement security enhancements following auditors suggestions:
Exclude disabled recipients from recipient selection and report delivery
Make whistleblower-identity access authorization definitive and tenant-scoped
Apply active maskings to the report listing to prevent a redaction bypass
Apply all redactions targeting a comment on consumption, not only the first
Enforce personal-comment ownership on redaction creation
Guard the answer and identity redaction paths against a missing descriptor
Bump the report update timestamp only after the masking permission check
Validate redaction range input at the handler
Bound answer-tree recursion depth to prevent a report-view denial of service
Restrict authtoken usage
Prevent lowering the encryption setting via the node settings API
Validate the wizard admin and recipient e-mail addresses
Overwrite the whole file during secure deletion - Fix tip access grant to return a consistent result for keyless recipients
- Improve unit tests in relation to data redaction
- Bump client dependencies to their latest stable versions
Security Fixes
- Authflow cooldowns now session‑scoped — closes abuse vector where users changed phone/email mid‑flow to reset OTP cooldowns
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About GlobaLeaks
Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
Related context
Related tools
Beta — feedback welcome: [email protected]