This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
Affected surfaces
ReleasePort's take
Moderate signalCVE-601 is fixed by scoping redirect URIs to the cookie domain in this release.
Why it matters: The fix for CVE-601 (severity 90) prevents unauthorized redirect URI abuse; update immediately if your application uses redirect URIs.
Summary
AI summaryUpdates Bug Fixes, 1.5.1, and 2026-07-10 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes CVE-601 by scoping redirect URIs to cookie domain Fixes CVE-601 by scoping redirect URIs to cookie domain Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bumps actions/cache from version 4 to 5 Bumps actions/cache from version 4 to 5 Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bumps actions/checkout from version 2 to 7 Bumps actions/checkout from version 2 to 7 Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bumps docker/build-push-action from version 6 to 7 Bumps docker/build-push-action from version 6 to 7 Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bumps docker/login-action from version 3 to 4 Bumps docker/login-action from version 3 to 4 Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bumps docker/setup-qemu-action from version 3 to 4 Bumps docker/setup-qemu-action from version 3 to 4 Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Addresses cippy issues Addresses cippy issues Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
1.5.1 (2026-07-10)
Bug Fixes
- cippy issues (d5fc249)
- CVE-601 vulnerabiilty. scope redirect uris to cookie domain (#71) (664f260)
- deps: bump actions/cache from 4 to 5 (#66) (266dce5)
- deps: bump actions/checkout from 2 to 7 (#62) (cce0015)
- deps: bump docker/build-push-action from 6 to 7 (#70) (b8849e7)
- deps: bump docker/login-action from 3 to 4 (#68) (a69ffd2)
- deps: bump docker/setup-qemu-action from 3 to 4 (#69) (f860e05)
Security Fixes
- CVE-601 — redirect URIs now scoped to the cookie domain
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About nforwardauth
Simple and minimalist forward auth service intended for use with reverse proxies (Traefik, Caddy, nginx, etc)
Related context
Related tools
Beta — feedback welcome: [email protected]