This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
Dashboards & Home Pages
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
atom
feed
go
jsonfeed
letsencrypt
opml
+3 more
postgresql
rdf
rss
Affected surfaces
auth
Summary
AI summaryUpdates Bug fixes, New features, and Performance improvements across a mixed release.
Full changelog
New features
-
Improved full-text search
- Search queries now use PostgreSQL's
websearch_to_tsquery, allowing quoted phrases,ORoperators, and negation (-term) in search expressions.
- Search queries now use PostgreSQL's
-
API improvements
- Added
GET /v1/entries/idsto efficiently retrieve paginated entry IDs. - Added support for updating the starred status of multiple entries through
PUT /v1/entries. - API clients can now filter entries by tags.
- The Go client now exposes additional feed fields (
description,icon,next_check_at, notification settings,no_media_player, etc.) and supports the new tag filter.
- Added
-
Atom feed improvements
- When an Atom entry
idcontains an HTTP URL, it is now used as the entry URL when no dedicated link is available.
- When an Atom entry
Performance improvements
- Improved full-text search performance by caching compiled regular expressions used by filtering rules.
- Reduced database work when computing category statistics.
- Improved browser caching of static assets.
- Reduced template rendering overhead by precomputing static icon URLs.
Security
- Prevent username enumeration through login timing differences.
- PostgreSQL installations running in FIPS mode are now fully supported by replacing MD5 with SHA-256 for enclosure uniqueness. This change raises the minimum supported PostgreSQL version to 11.
Bug fixes
- Fixed validation of per-feed entry filter rules in the web interface.
- SOCKS proxy URLs can once again be configured for individual feeds.
- Fixed enclosure URL proxying consistency across API endpoints.
- Fixed several API handlers that incorrectly returned
404 Not Foundor400 Bad Requestinstead of proper server errors. - Fixed inconsistent handling of invalid category filters in the Entries API.
- Fixed user lookup edge cases that could result in nil pointer dereferences.
- Fixed enclosure lookup to correctly scope results by user.
- Fixed the Google Reader Quick Add endpoint to honor the configured HTTP user agent.
- Fixed refresh-all keyboard shortcut (
R) to correctly display the success notification. - Fixed localization formatting issues affecting several languages.
- Fixed request builder state leaking during feed discovery.
- Improved accessibility by correcting an
aria-labelledbyissue.
Localization
- Updated German (
de_DE) translations. - Updated Galician (
gl_ES) translations.
Documentation
- Clarified the units for
POLLING_FREQUENCY. - Improved documentation for
TRUSTED_REVERSE_PROXY_NETWORKS.
Dependencies
- Updated several Go modules and GitHub Actions dependencies.
Breaking Changes
- Minimum supported PostgreSQL version raised to 11
Security Fixes
- Prevent username enumeration through login timing differences
- Replace MD5 with SHA-256 for enclosure uniqueness in FIPS‑mode PostgreSQL (requires version >=11)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]