This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
Summary
AI summaryHardened server against SSRF, path traversal, resource exhaustion and added DNS rebinding protection.
Full changelog
v2.9.5 (2026-03-03)
This release is published under the MIT License.
Bug Fixes
-
security: DNS rebinding protection via pinned getaddrinfo cache (
d66afeb) -
security+perf: Harden server against SSRF, path traversal, resource exhaustion and optimize DB queries (
d66afeb)
Detailed Changes: v2.9.4...v2.9.5
Security Fixes
- DNS rebinding protection via pinned getaddrinfo cache
- Hardened server against SSRF, path traversal, and resource exhaustion
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/wet-mcp
Web search (embedded SearXNG), content extraction, and library docs indexing with hybrid search (FTS5 + semantic). Built-in Qwen3 embedding, no API keys required.
Related context
Beta — feedback welcome: [email protected]