Skip to content

Nenya

v0.6.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo LLM Frameworks
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-gateway ai-governance ai-proxy ai-safety ai-security
+14 more
ai-tools anthropic deepseek litellm-alternative llm llm-gateway observability ollama openai openai-compatible-api openai-proxy opencode-zen proxy zhipu-ai

Affected surfaces

auth rce_ssrf

Summary

AI summary

Security hardening adds bounds to unbounded io.ReadAll calls and improves path validation.

Full changelog

Changelog

  • 10ee5f534bbf0799ad4840e348418367b563fce0 Merge phase-010-streaming-cache-adapter into main
  • 99fafa72bc3bafb7b3e8e5710e5ea017b69529da Merge phase-011-testutil-cleanup into main
  • c0ff0f54d534d83ad1205a822b8bc241cc70abf5 Merge phase-012-security-fixes into main
  • a8cb265c66c621b118492e8307f0628df98ab307 Merge phase-013-concurrency-fixes into main
  • 59593c247253c53dfa3692f43c246c0233f310f7 Merge phase-015-duplication-fixes into main
  • 38fc0369cb9e512e927c34727646fa9e3af7a09b cleanup: remove dead testutil code and unused production functions
  • f2baca0944ba261ee006683b9cec949981eb29c2 concurrency: fix data races, lock-during-IO, and goroutine lifecycle
  • 0ddf6a2b119f1d3a2f1137b3b2235e2b71aea6f9 fix: address 5 regressions introduced since Phase 010
  • 73ad57e20444b850ac026b497c19302385b255df fix: correct UnloadModel TOCTOU logic (inverted condition)
  • 9c56a94b6e47dca885749c159ec3060c9f944092 fix: streaming, cache, and Anthropic adapter bugs (issues #17-#20)
  • f918917b91e8dee4a8b6e989a11f6e53064d7b7d perf: apply Phase 017 metrics refactor (labelEscaper, Grow, histogram fix)
  • cd9623bd7579091f5ec9e607eb7d1e887fbccbe7 phase-014: complete chat decomposition — extract responses.go and mcp_loop.go
  • a876b8b58c1fff9b026124850d1621a3f20aa6cd phase-014: partial chat decomposition — extract constants, embeddings, usage
  • 78cd3831da3efb6aedb6f5400341f09a967f8380 security: add bounds to unbounded io.ReadAll calls and harden path validation

Security Fixes

  • Added bounds to unbounded `io.ReadAll` calls and hardened path validation

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Nenya

Get notified when new releases ship.

Sign up free

About Nenya

All releases →

Beta — feedback welcome: [email protected]