Skip to content

metube

v2026.07.21 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 6d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

self-hosted youtube youtube-dl yt-dlp

Affected surfaces

rbac rce_ssrf

Summary

AI summary

Updates fix, e061a8a, and feat across a mixed release.

Full changelog

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.07.21

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.07.21

Changes

  • feat: ALLOW_PRIVATE_ADDRESSES to opt out of the SSRF checks (closes #1036) (e061a8a)
  • docs: document the SSRF guard's connect-time coverage limitations (13cb65d)
  • fix: re-validate outbound connections at fetch time against internal hosts (1b02a99)
  • fix: fail closed when an SSRF-guarded host cannot be resolved (ebcfe57)
  • fix: enforce download-dir containment at the resolved-path chokepoint (3bd2c3e)
  • ci: update releases in place instead of delete-and-recreate (707f700)
  • chore: rework issue and discussion templates around scope policy (c519f45)

Security Fixes

  • Re-validate outbound connections at fetch time against internal hosts
  • Fail closed when an SSRF-guarded host cannot be resolved
  • Enforce download-dir containment at the resolved-path chokepoint

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track metube

Get notified when new releases ship.

Sign up free

About metube

Self-hosted video downloader for YouTube and other sites (web UI for youtube-dl / yt-dlp)

All releases →

Beta — feedback welcome: [email protected]