This release includes 5 security fixes for security teams reviewing exposed deployments.
Published 3mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 5 known CVEs
Topics
appointment
appointment-booking
appointment-scheduling
appointments
calendar
calendars
+6 more
calendly-alternative
docker
elixir
phoenix-liveview
postgresql
scheduling
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summaryAdd Italian language support for bookings and emails.
Full changelog
[0.100.10] — 2026-04-21
Bug Fixes
- core: Count all concurrent failed login attempts toward account lockout
- core: Restore meeting-type creation when no calendar is selected
- core: Deliver attendee notifications on calendar event updates
- core: Prevent password-reset race that could overwrite a user's new password
- core: Prevent availability crash on DST-transition break times
- core: Collapse duplicate time slot labels on daylight-saving fall-back days
- core: Prevent CalDAV sync crash on malformed server responses
- core: Honour :already_scheduled dedup contract in CalendarJobs
- core: Reject double-encoded open-redirect payloads
- core: Sign pagination cursors to prevent forged keyset offsets
- core: Block webhook delivery redirects to private networks
- core: Flag calendar integrations for reauth on decryption failure
- core: Preserve circuit-breaker state across worker restarts
- core: Keep account lockout counter in effect across restarts
- core: Block XSS via custom theme CSS breakout
- core: Require OAuth callback state to match session user
Features
- core: Add Italian to supported booking and email languages
Security Fixes
- Reject double‑encoded open‑redirect payloads
- Sign pagination cursors to prevent forged keyset offsets
- Block webhook delivery redirects to private networks
- Require OAuth callback state to match session user
- Block XSS via custom theme CSS breakout
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]