Skip to content

pocketbase

v0.39.6 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 19d API Development
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

authentication backend go realtime

Affected surfaces

auth deps

Summary

AI summary

Added Cc and Bcc support to dev sendmail, hardened MS OAuth2 email extraction options.

Full changelog

To update the prebuilt executable you can run ./pocketbase update.

  • Added Cc and Bcc recipients to the dev sendmail command for consistency with the SMTP mailer.

  • Added extra hardening options to the Microsoft OAuth2 provider allowing developers to specify the preferred safe email extraction method (#7756).

  • Updated goja and the related golang.org/x/* dependencies (WeakMap regression fixes).

  • Bumped the min Go GitHub action version to 1.26.5 as it includes some minor security fixes.

Security Fixes

  • dep: goja and golang.org/x/* dependencies updated; includes minor security fixes from Go 1.26.5 (GitHub Action version bump).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track pocketbase

Get notified when new releases ship.

Sign up free

About pocketbase

Open Source realtime backend in 1 file

All releases →

Related context

Earlier breaking changes

  • v0.39.4 Removes required validator for redirectURL in authWithOAuth2Code endpoint

Beta — feedback welcome: [email protected]