This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
LLM Frameworks
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
ai-gateway
ai-governance
ai-proxy
ai-safety
ai-security
+14 more
ai-tools
anthropic
deepseek
litellm-alternative
llm
llm-gateway
observability
ollama
openai
openai-compatible-api
openai-proxy
opencode-zen
proxy
zhipu-ai
Affected surfaces
auth
rce_ssrf
Summary
AI summarySecurity hardening adds bounds to unbounded io.ReadAll calls and improves path validation.
Full changelog
Changelog
- 10ee5f534bbf0799ad4840e348418367b563fce0 Merge phase-010-streaming-cache-adapter into main
- 99fafa72bc3bafb7b3e8e5710e5ea017b69529da Merge phase-011-testutil-cleanup into main
- c0ff0f54d534d83ad1205a822b8bc241cc70abf5 Merge phase-012-security-fixes into main
- a8cb265c66c621b118492e8307f0628df98ab307 Merge phase-013-concurrency-fixes into main
- 59593c247253c53dfa3692f43c246c0233f310f7 Merge phase-015-duplication-fixes into main
- 38fc0369cb9e512e927c34727646fa9e3af7a09b cleanup: remove dead testutil code and unused production functions
- f2baca0944ba261ee006683b9cec949981eb29c2 concurrency: fix data races, lock-during-IO, and goroutine lifecycle
- 0ddf6a2b119f1d3a2f1137b3b2235e2b71aea6f9 fix: address 5 regressions introduced since Phase 010
- 73ad57e20444b850ac026b497c19302385b255df fix: correct UnloadModel TOCTOU logic (inverted condition)
- 9c56a94b6e47dca885749c159ec3060c9f944092 fix: streaming, cache, and Anthropic adapter bugs (issues #17-#20)
- f918917b91e8dee4a8b6e989a11f6e53064d7b7d perf: apply Phase 017 metrics refactor (labelEscaper, Grow, histogram fix)
- cd9623bd7579091f5ec9e607eb7d1e887fbccbe7 phase-014: complete chat decomposition — extract responses.go and mcp_loop.go
- a876b8b58c1fff9b026124850d1621a3f20aa6cd phase-014: partial chat decomposition — extract constants, embeddings, usage
- 78cd3831da3efb6aedb6f5400341f09a967f8380 security: add bounds to unbounded io.ReadAll calls and harden path validation
Security Fixes
- Added bounds to unbounded `io.ReadAll` calls and hardened path validation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Nenya
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]