This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Secrets & Credentials
✓ No known CVEs patched
This release patches 1 known CVE
Topics
authentication
ldap
opaque
rust
security
wasm
+1 more
web-assembly
Summary
AI summaryUpdated LDAP dependency stack to address a crash vulnerability from specially crafted queries.
Full changelog
[0.6.3] 2026-05-01
Small release, focused on LDAP compatibility, TLS maintenance, dependency upgrades and documentation/examples.
Added
- LDAP schema definitions for
memberOf,modifyTimestampandpwdChangedTime - Support for configuring the healthcheck listen addresses
- Usernames are now included in password recovery emails
Changed
- JWT
expandiatclaims are now serialized as NumericDate values to comply with RFC7519 - Migrated to
rustls0.23 and centralized TLS handling - The login form no longer enforces a password length limit
Fixed
pwdChangedTimeis now emitted as LDAP GeneralizedTime instead of RFC3339- LDAP base-scope searches for non-existent entries now return
NoSuchObject cnequality filters are now case insensitive- The server now shuts down the database connection pool gracefully
- The bootstrap script now handles empty globs correctly
Security
- Updated the LDAP dependency stack, including
ldap3_proto, in response to
security advisory
GHSA-qcxq-75wr-5cm8,
where a specially crafted LDAP query could make the server crash
Cleanups
- Split GraphQL queries and mutations into smaller modules
- Refactored configuration and user update logic
- Upgraded the Rust toolchain and shared dependencies
New services
- Apache WebDAV
- Continuwuity
- Gerrit
- Gogs
- Open WebUI
- OpenCloud
- Pocket ID
- Semaphore
- TrueNAS
Security Fixes
- dep: GHSA-qcxq-75wr-5cm8 — Updated LDAP dependency stack (including ldap3_proto) to prevent crash from specially crafted LDAP queries
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]