This release includes 4 security fixes for security teams reviewing exposed deployments.
Published 1mo
Monitoring & Metrics
✓ No known CVEs patched
This release patches 4 known CVEs
Topics
analytics
monitoring
notifications
plex
plexpy
python
+3 more
statistics
stats
tautulli
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates v2.17.2, Fix, and 2026-06-16 across a mixed release.
Full changelog
Changelog
v2.17.2 (2026-06-16)
- Notifications:
- Fix: Line breaks in Gotify notification body text. (#2702)
- Newsletters:
- Fix: XSS in newsletter cron value. (CVE-2026-49995) (Thanks @elvinsuleymanov)
- UI:
- Fix: Reflected XSS in search query string. (CVE-2026-45381) (Thanks @JakePeralta7, @sondt99, @kah-ja)
- Fix: Duplicated activity card progress timers. (#2716) (Thanks @omglazrgunpewpew)
- Other:
- Fix: Fix X-Api-Key header check crashing server. (#2711)
- Fix: Path traversal in uploaded database and config file names. (CVE-2026-52835) (Thanks @tonghuaroot)
- Fix: Empty host fallback in URL when launching browser. (#2722) (Thanks @upmcplanetracker)
- Fix: Open redirect via whitespace bypass in /auth/redirect (CVE-2026-54915) (Thanks @sondt99)
🛡 VirusTotal GitHub Action analysis:
Security Fixes
- CVE-2026-45381 — Reflected XSS in search query string
- CVE-2026-49995 — XSS in newsletter cron value
- CVE-2026-52835 — Path traversal in uploaded database and config file names
- CVE-2026-54915
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]