Skip to content

v2

v2.3.2 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

atom feed go jsonfeed letsencrypt opml
+3 more
postgresql rdf rss

Affected surfaces

auth

Summary

AI summary

Updates Bug fixes, New features, and Performance improvements across a mixed release.

Full changelog

New features

  • Improved full-text search

    • Search queries now use PostgreSQL's websearch_to_tsquery, allowing quoted phrases, OR operators, and negation (-term) in search expressions.
  • API improvements

    • Added GET /v1/entries/ids to efficiently retrieve paginated entry IDs.
    • Added support for updating the starred status of multiple entries through PUT /v1/entries.
    • API clients can now filter entries by tags.
    • The Go client now exposes additional feed fields (description, icon, next_check_at, notification settings, no_media_player, etc.) and supports the new tag filter.
  • Atom feed improvements

    • When an Atom entry id contains an HTTP URL, it is now used as the entry URL when no dedicated link is available.

Performance improvements

  • Improved full-text search performance by caching compiled regular expressions used by filtering rules.
  • Reduced database work when computing category statistics.
  • Improved browser caching of static assets.
  • Reduced template rendering overhead by precomputing static icon URLs.

Security

  • Prevent username enumeration through login timing differences.
  • PostgreSQL installations running in FIPS mode are now fully supported by replacing MD5 with SHA-256 for enclosure uniqueness. This change raises the minimum supported PostgreSQL version to 11.

Bug fixes

  • Fixed validation of per-feed entry filter rules in the web interface.
  • SOCKS proxy URLs can once again be configured for individual feeds.
  • Fixed enclosure URL proxying consistency across API endpoints.
  • Fixed several API handlers that incorrectly returned 404 Not Found or 400 Bad Request instead of proper server errors.
  • Fixed inconsistent handling of invalid category filters in the Entries API.
  • Fixed user lookup edge cases that could result in nil pointer dereferences.
  • Fixed enclosure lookup to correctly scope results by user.
  • Fixed the Google Reader Quick Add endpoint to honor the configured HTTP user agent.
  • Fixed refresh-all keyboard shortcut (R) to correctly display the success notification.
  • Fixed localization formatting issues affecting several languages.
  • Fixed request builder state leaking during feed discovery.
  • Improved accessibility by correcting an aria-labelledby issue.

Localization

  • Updated German (de_DE) translations.
  • Updated Galician (gl_ES) translations.

Documentation

  • Clarified the units for POLLING_FREQUENCY.
  • Improved documentation for TRUSTED_REVERSE_PROXY_NETWORKS.

Dependencies

  • Updated several Go modules and GitHub Actions dependencies.

Breaking Changes

  • Minimum supported PostgreSQL version raised to 11

Security Fixes

  • Prevent username enumeration through login timing differences
  • Replace MD5 with SHA-256 for enclosure uniqueness in FIPS‑mode PostgreSQL (requires version >=11)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track v2

Get notified when new releases ship.

Sign up free

About v2

Minimalist and opinionated feed reader

All releases →

Related context

Beta — feedback welcome: [email protected]