This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalThe v4.3.6 release hardens outbound HTTP clients by refusing redirects and adds an NVIDIA NeMo Parakeet ASR backend.
Why it matters: Security: refuse redirects on all outbound HTTP client calls (severity 90). Feature: new ASR backend available (severity 40).
Summary
AI summaryUpdates Other Changes, chore, and http across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Refuse redirects on outbound HTTP clients for security hardening Refuse redirects on outbound HTTP clients for security hardening Source: llm_adapter@2026-05-30 Confidence: high |
— |
| Feature | Medium |
Adds NVIDIA NeMo Parakeet ASR backend (parakeet.cpp) Adds NVIDIA NeMo Parakeet ASR backend (parakeet.cpp) Source: llm_adapter@2026-05-30 Confidence: high |
— |
Full changelog
What's Changed
Other Changes
- chore: :arrow_up: Update ggml-org/llama.cpp to
22d66b567eef11cf2e9832f04db64ee0323a0fd0by @localai-bot in https://github.com/mudler/LocalAI/pull/10080 - security(http): refuse redirects on outbound clients via hardened pkg/httpclient by @richiejp in https://github.com/mudler/LocalAI/pull/10087
- feat(parakeet-cpp): add NVIDIA NeMo Parakeet ASR backend (parakeet.cpp) by @localai-bot in https://github.com/mudler/LocalAI/pull/10084
- chore: :arrow_up: Update antirez/ds4 to
e16ead1e29c81a67bbb64e5b001117679cf9ce6eby @localai-bot in https://github.com/mudler/LocalAI/pull/10076 - chore: :arrow_up: Update mudler/parakeet.cpp to
30a307553f1965ceb38a1a922069a71e7dd67bf3by @localai-bot in https://github.com/mudler/LocalAI/pull/10092
Full Changelog: https://github.com/mudler/LocalAI/compare/v4.3.5...v4.3.6
Security Fixes
- Refuse redirects on outbound clients via hardened pkg/httpclient (http security)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LocalAI
LocalAI is the open-source AI engine. Run any model - LLMs, vision, voice, image, video - on any hardware. No GPU required.
Related context
Related tools
Beta — feedback welcome: [email protected]