This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 27d
API Development
β No known CVEs patched
This release patches 2 known CVEs
Topics
authentication
backend
backend-as-a-service
database
firebase
flutter
+12 more
graphql
hasura
javascript
nextjs
nhost
postgresql
react
serverless
serverless-functions
storage
typescript
vue
Affected surfaces
deps
auth
Summary
AI summaryUpdates π Bug Fixes, deps, and Chore across a mixed release.
Full changelog
[@nhost/[email protected]] - 2026-06-29
π Bug Fixes
- (deps) Bump up shellquote due to CVE (#4499)
- (auth) Hash email OTP, make it single-use, and shorten its TTL (#4421)
- (storage) Bound transform dimensions and blur (#4445)
βοΈ Miscellaneous Tasks
- (nixops) Scope pinned toolchain overlays (#4506)
Chore
- (deps) Update vulnerable dependencies (#4530)
- (deps) Update vulnerable dependencies (#4541)
Security Fixes
- Bump shellquote to address CVE (#4499)
- (auth) Hash email OTP, enforce singleβuse, reduce TTL (#4421)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]