Skip to content

Tymeslot

v0.100.10 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

Published 3mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

appointment appointment-booking appointment-scheduling appointments calendar calendars
+6 more
calendly-alternative docker elixir phoenix-liveview postgresql scheduling

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Add Italian language support for bookings and emails.

Full changelog

[0.100.10] — 2026-04-21

Bug Fixes

  • core: Count all concurrent failed login attempts toward account lockout
  • core: Restore meeting-type creation when no calendar is selected
  • core: Deliver attendee notifications on calendar event updates
  • core: Prevent password-reset race that could overwrite a user's new password
  • core: Prevent availability crash on DST-transition break times
  • core: Collapse duplicate time slot labels on daylight-saving fall-back days
  • core: Prevent CalDAV sync crash on malformed server responses
  • core: Honour :already_scheduled dedup contract in CalendarJobs
  • core: Reject double-encoded open-redirect payloads
  • core: Sign pagination cursors to prevent forged keyset offsets
  • core: Block webhook delivery redirects to private networks
  • core: Flag calendar integrations for reauth on decryption failure
  • core: Preserve circuit-breaker state across worker restarts
  • core: Keep account lockout counter in effect across restarts
  • core: Block XSS via custom theme CSS breakout
  • core: Require OAuth callback state to match session user

Features

  • core: Add Italian to supported booking and email languages

Security Fixes

  • Reject double‑encoded open‑redirect payloads
  • Sign pagination cursors to prevent forged keyset offsets
  • Block webhook delivery redirects to private networks
  • Require OAuth callback state to match session user
  • Block XSS via custom theme CSS breakout

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Tymeslot

Get notified when new releases ship.

Sign up free

About Tymeslot

Privacy-first scheduling platform

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]