This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
Summary
AI summaryUpdates Internal, multi-source, and Tests across a mixed release.
Full changelog
Keyless onboarding: per-identity IP grace
Replaces the per-(identity, tool) first-swipe exemption with a single 24h grace window per keyless identity. A new caller can now exercise every cost==1 MCP tool freely during the window instead of exhausting the shared hourly quota partway through a discovery pass; once the window elapses the identity falls back to the standard free hourly limit.
- Composite (multi-source) tools, API-key callers, and REST requests are never graced.
- IPv6 identities are bucketed to a /64; in-window traffic is metered against a separate high per-identity ceiling as a DoS backstop.
- The window's start is recorded once and never reset.
Fixes
- /welcome: the
order_idquery parameter is normalized to its canonical UUID form, making key lookups robust to non-canonical spellings (upper-case / braces / urn:) and closing a CodeQL log-injection alert on the render-failure path.
Internal
- Tests: the first-swipe suite is replaced by a 22-case IP-grace suite; full suite 2602 passing.
- MCP surface unchanged: 54 tools, 7 Resources, 3 Prompts.
Security Fixes
- /welcome order_id normalization closes CodeQL log‑injection alert
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About UPinar/contrastapi
Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.
Related context
Related tools
Earlier breaking changes
- v1.33.11 `bulk_sigma_rule_lookup` now costs 1 credit per `rule_id`, changing from flat 1 credit/call.
Beta — feedback welcome: [email protected]