Skip to content

Pingvin Share X

v1.21.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 9d File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

docker fileshare fork self-hosted share

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 9d

Patch over 40 curl vulnerabilities in the build workflow and align reverse share size limits with settings.

Why it matters: Patching resolves >40 high‑severity curl flaws affecting package builds; alignment fixes UI mismatch for share size limits.

Summary

AI summary

Patch over 40 curl vulnerabilities and align reverse share size limits with settings.

Changes in this release

Security Critical

Patches 40+ curl vulnerabilities in the build workflow

Patches 40+ curl vulnerabilities in the build workflow

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Correctly detect disk usage on mounted Linux filesystems

Correctly detect disk usage on mounted Linux filesystems

Source: llm_adapter@2026-07-17

Confidence: high

Bugfix Medium

Align max share size modal with user/global settings

Align max share size modal with user/global settings

Source: llm_adapter@2026-07-17

Confidence: high

Full changelog

What's Changed

  • fix(system): correctly detect disk usage on mounted filesystems (linux) by @patrickpilotti in https://github.com/smp46/pingvin-share-x/pull/126
  • fix(reverseShares): align max share size in modal with user/global settings by @AlekseyLapunov in https://github.com/smp46/pingvin-share-x/pull/136
  • chore(translations): update translations via Crowdin in https://github.com/smp46/pingvin-share-x/pull/117

This release will patch many (40+) related curl vulnerabilities left as a result of aggressive caching, changes to the build workflow mean from now on it will always fetch the most up-to-date packages for the final image. As well as patching all non NextJS 14 Vulnerabilities (majority of which are irrelevant to this project). 🎉

New Contributors

  • @patrickpilotti made their first contribution in https://github.com/smp46/pingvin-share-x/pull/126
  • @AlekseyLapunov made their first contribution in https://github.com/smp46/pingvin-share-x/pull/136

Full Changelog: https://github.com/smp46/pingvin-share-x/compare/v1.21.0...v1.21.1

Security Fixes

  • Patch >40 curl vulnerabilities caused by aggressive caching; ensure latest secure curl version is used in the build
  • Address all non NextJS 14 vulnerabilities applicable to this project

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Pingvin Share X

Get notified when new releases ship.

Sign up free

About Pingvin Share X

File sharing platform and WeTransfer alternative

All releases →

Related context

Beta — feedback welcome: [email protected]