This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
form
quiz
survey
Affected surfaces
rce_ssrf
Summary
AI summaryFixed server-side request forgery guard to block alternate IPv6 address encodings.
Full changelog
What's Changed
- fix(server): block alternate IPv6 encodings in outbound SSRF guard by @joeltco in https://github.com/heyform/heyform/pull/285
New Contributors
- @joeltco made their first contribution in https://github.com/heyform/heyform/pull/285
Full Changelog: https://github.com/heyform/heyform/compare/v3.0.0-rc.8...v3.0.0-rc.9
Security Fixes
- Fixed SSRF guard to block alternate IPv6 encodings
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]