Skip to content

spupuz/VibeNVR

v1.31.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 6d Media Servers
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

ffmpeg lightweight local-storage nvr opensource privacy
+1 more
video-surveillance

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates πŸ› οΈ Key Improvements, πŸš€ Release v1.31.0, and πŸ™Œ Contributors across a mixed release.

Full changelog

πŸš€ Release v1.31.0

πŸ“ Summary

This minor release introduces native Single Sign-On (SSO / OAuth 2.0) integration into VibeNVR, bringing enterprise-grade identity management to your deployments. Alongside these major authentication features, we have patched a critical security vulnerability affecting webhook transmissions.

πŸ› οΈ Key Improvements

  • πŸš€ Authentication (SSO & OIDC): Introduced full support for OAuth 2.0 and OpenID Connect. You can now link your VibeNVR local accounts to external Identity Providers (such as Authentik, Keycloak, or Google Workspace) using a strict Zero-Trust subject mapping.
  • ✨ SSO Auto-Redirect & RP-Logout: Added the ability to enable Auto-Redirect, which seamlessly bypasses the local login screen to immediately prompt your IdP. We also introduced RP-Initiated Logout, ensuring that logging out of VibeNVR securely terminates your session at the provider level.
  • πŸ›‘οΈ Security (Webhooks): Fixed a HIGH severity Server-Side Request Forgery (SSRF) bypass in webhook transmissions. The engine now explicitly blocks malicious redirects to internal IP addresses (e.g., Cloud Metadata).

πŸ™Œ Contributors

  • @spupuz: πŸ›‘οΈ Fixed the critical SSRF vulnerability in webhooks (PR #230) and championed the new SSO architecture.

Security Fixes

  • CVE-2024-XXXXX β€” Fixed high‑severity Server‑Side Request Forgery (SSRF) bypass in webhook transmissions, now blocks redirects to internal IP addresses such as cloud metadata services

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spupuz/VibeNVR

Get notified when new releases ship.

Sign up free

About spupuz/VibeNVR

All releases β†’

Related context

Earlier breaking changes

  • v1.29.7 Removed the legacy `stream_url` schema from stream routing.
  • v1.28.3 Must update docker-compose.yml with TZ variable for all services

Beta — feedback welcome: [email protected]