Skip to content

nzbget

v26.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

nzbget usenet

Affected surfaces

auth rce_ssrf

Summary

AI summary

Broad release touches CI, i18n, https://github.com/nzbgetcom/nzbget/pull/813, and https://github.com/nzbgetcom/nzbget/pull/794.

Full changelog

What's Changed

  • Features:

    • WebUI internationalisation (i18n) and unit switching #813
      • Added client-side i18n engine with locale loading, language detection, and DOM translation via data-i18n attributes;
      • Unit switching for network speed display (MB/s <-> Mb/s);
      • Added per-language translation files for 20 languages;
      • Added an indicator icon alignment in the Downloads table headers;
      • Improved text readability — config description help blocks now preserve original formatting from nzbget.conf;
      • Improved layout adaptability and responsiveness;
    • Added support for ~/.config config locations #794
    • Added 'This Year' total to bandwidth usage on statistics #801
    • Added Clear button to History page #804
    • nserv: log datetime #717
  • Bug fixes:

    • Fixed handling of server speed tests bound to a specific server #781
    • Fixed auto-category overriding manual category via CLI #787
    • Fixed SystemHealth validators #791
    • Fixed SkipWrite option #792
    • Fixed iPadOS file uploads and sanitized DOM inputs to prevent XSS vulnerability #793
    • Fixed macOS dark mode readable text and NZB file association #795
    • Fixed RSS feed text fragmentation causing whitespace loss in element content #796
    • Fixed WebUI RSS "Add" dialog ignoring item-level category when CategorySource is NZBFile or Auto #827
    • Prevented symlink attacks and TOCTOU races in daemon startup #798
    • Fixed new-version flag to only trigger on same update channel #800
    • Fixed iOS auto-capitalizing the login username field #805
    • Suppressed WriteLog info/warning health checks and added LoggingValidator tests #803
    • Fixed hanging server speed tests #807
    • Fixed resource leaks in socket/listener and script pipe error paths #797
    • Fixed WebUI "InternalError: allocation size overflow" on very large file uploads #818
  • For developers:

    • Fixed missing nzbget.h include order in Cleanup.cpp #782
    • CI: added build-disabled-pch job to verify compilation works without PCH #783
    • CI: changed 7-zip sources from 7-zip.org to GitHub #786
    • CI: fixed latest artifacts creation #790
    • Updated 7-Zip to 26.01 and UnRAR to 7.21 #802
    • Bumped UnRAR to 7.22 (Windows/macOS only) #822

Security Fixes

  • Fixed iPadOS file uploads and sanitized DOM inputs to prevent XSS vulnerability [#793]

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track nzbget

Get notified when new releases ship.

Sign up free

About nzbget

Efficient usenet downloader

All releases →

Beta — feedback welcome: [email protected]