This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalThe release adds protection against timing attacks on the notification unsubscribe endpoint.
Why it matters: Mitigates a critical security risk (severity 80) for the notification unsubscribe surface; operators should apply the update immediately.
Summary
AI summaryAdded protection against timing attacks on notification unsubscribe endpoints.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Adds protection against timing attacks on notification unsubscribe endpoints. Adds protection against timing attacks on notification unsubscribe endpoints. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Adds admin interface to change user avatars. Adds admin interface to change user avatars. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Adds automatic metrics tagging of outgoing emails. Adds automatic metrics tagging of outgoing emails. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Increases valid user‑supplied URL length to 1024 characters. Increases valid user‑supplied URL length to 1024 characters. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Medium |
Adds email verification check during sign‑in flow. Adds email verification check during sign‑in flow. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Feature | Low |
Enables drag-and-drop from document lists. Enables drag-and-drop from document lists. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Feature | Low |
Allows collection managers to approve access requests. Allows collection managers to approve access requests. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Feature | Low |
Makes collection title and icon inline editable like documents. Makes collection title and icon inline editable like documents. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Performance | Medium |
Improves worker performance through caching. Improves worker performance through caching. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Fixes search term highlights missing on navigation from search. Fixes search term highlights missing on navigation from search. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Fixes intermittent sidebar element not active on first load. Fixes intermittent sidebar element not active on first load. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Prevents scrollbar from causing horizontal movement in comments sidebar. Prevents scrollbar from causing horizontal movement in comments sidebar. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Adds handling of unhandled server error in MCP route. Adds handling of unhandled server error in MCP route. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Low |
Prevents icon picker from auto-closing on choice. Prevents icon picker from auto-closing on choice. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Bugfix | Low |
Fixes sticky table header styling in Safari. Fixes sticky table header styling in Safari. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Bugfix | Low |
Treats private IP lookup as invalid request instead of internal error. Treats private IP lookup as invalid request instead of internal error. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Bugfix | Low |
Resolves iterable error for collaboratorIds with very old documents. Resolves iterable error for collaboratorIds with very old documents. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Bugfix | Low |
Fixes correct support for hard break serialization in commonMark. Fixes correct support for hard break serialization in commonMark. Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
Full changelog
What's Changed
Improvements
- Drag-and-drop now supports dragging from document lists in https://github.com/outline/outline/pull/12587
- Add admin interface to change user avatars in https://github.com/outline/outline/pull/12405
- Add automatic metrics tagging of outgoing emails in https://github.com/outline/outline/pull/12570
- Various improvements to mobile styling and layout in https://github.com/outline/outline/pull/12577, https://github.com/outline/outline/pull/12576
Fixes
- Fixed search term highlights missing on navigation from search in https://github.com/outline/outline/pull/12598
- Fixed an intermitent issue where sidebar element is not correctly active on first load in https://github.com/outline/outline/pull/12566
- Scrollbar no longer causes horizontal movement in comments sidebar in https://github.com/outline/outline/pull/12565
- Added protection against timing attacks on notification unsubscribe endpoints in https://github.com/outline/outline/pull/12551
- Icon picker is no longer auto-closed on choice in https://github.com/outline/outline/pull/12573
- Access requests can now be approved by collection managers in https://github.com/outline/outline/pull/12579
- Collection title and icon inline are now editable like documents in https://github.com/outline/outline/pull/12574
- Increased valid user-supplied URL length to 1024 in https://github.com/outline/outline/pull/12585
- Added handling of unhandled server error in MCP route in https://github.com/outline/outline/pull/12586
- Fixed sticky table header styling in Safari in https://github.com/outline/outline/pull/12590
- Private IP lookup is now invalid request rather than internal error in https://github.com/outline/outline/pull/12592
- Improved worker performance through caching in https://github.com/outline/outline/pull/12593
- chore: Improve handling of "expected" network errors from webhooks in https://github.com/outline/outline/pull/12599
- Mermaid is no longer persisted as last used coding language in https://github.com/outline/outline/pull/12601
- Fixed
collaboratorIdsiterable error when handling very old documents in https://github.com/outline/outline/pull/12602 - Fixed correct support for hard break serialization for commonMark in https://github.com/outline/outline/pull/12603
- Added email verification check during sign-in flow in https://github.com/outline/outline/pull/12605
Full Changelog: https://github.com/outline/outline/compare/v1.8.0...v1.8.1
Security Fixes
- Added protection against timing attacks on notification unsubscribe endpoints (GHSA‑f3c9‑4g2b‑6w7r)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About outline
The fastest knowledge base for growing teams. Beautiful, realtime collaborative, feature packed, and markdown compatible.
Related context
Beta — feedback welcome: [email protected]