This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 2d
Dashboards & Home Pages
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
atom
feed
go
jsonfeed
letsencrypt
opml
+3 more
postgresql
rdf
rss
Affected surfaces
auth
Summary
AI summaryUpdates Bug fixes, New features, and Performance improvements across a mixed release.
Full changelog
New features
-
Feed and entry language detection
- Miniflux now reads the language declared by feeds and entries and stores it on both feeds and entries. Supported sources are the RSS
<language>and<dc:language>elements,xml:langon Atom 1.0 and 0.3 documents,dc:languagein RDF/RSS 1.0 feeds, and thelanguagefield of JSON Feed. - Entries without their own language now inherit the language declared by the feed.
- Article titles and content are rendered with a matching
langattribute, which improves screen reader pronunciation, hyphenation, and browser translation prompts. - The
languagefield is exposed through the API and the Go client for both feeds and entries.
- Miniflux now reads the language declared by feeds and entries and stores it on both feeds and entries. Supported sources are the RSS
-
Other additions
- Feed discovery now finds the feeds offered by GitHub pages.
- TLS certificates are reloaded when the process receives
SIGHUP, so renewed certificates can be picked up without a restart. - The browser favicon is now served as SVG for a sharper icon on high-density displays.
- Compressed responses are negotiated with a much more standard-compliant
Accept-Encodingparser, including quality values and wildcards.
Performance improvements
- Long entry and feed lists render noticeably faster: off-screen rows no longer cost layout and paint work on initial render.
- Reduced memory allocations when stripping and truncating HTML, roughly halving the time spent on tag-heavy content.
- Compression writers are now pooled instead of being allocated for every compressed response, which significantly reduces garbage collection pressure on busy instances.
Security
- Fixed an information disclosure issue where any authenticated user could read favicons belonging to other users' feeds through
GET /v1/icons/{iconID}. - Unix sockets are now created with
0660permissions instead of being world-writable. Deployments where the reverse proxy runs as a different user now require that user to share a group with the Miniflux process. - Fixed an issue where
limit=0in entry queries bypassed the 1000-entry cap and returned every matching entry. - Feed-declared language values are now validated before being stored, keeping oversized values and control characters out of the database and the rendered HTML.
Bug fixes
- Fixed a crash caused by concurrent writes to the translation catalog when several requests used a not-yet-loaded language.
- Fixed a race condition during template rendering that could return a page translated in another user's language.
- Fixed a panic during graceful shutdown when feed refresh jobs were queued while workers were draining.
- Fixed a division-by-zero crash with the
entry_frequencyscheduler whenSCHEDULER_ENTRY_FREQUENCY_FACTORwas set to0; the value must now be greater than or equal to1. - Fixed an upgrade failure of migration 127 on databases containing entries whose feed no longer exists.
MEDIA_PROXY_RESOURCE_TYPESandTRUSTED_REVERSE_PROXY_NETWORKSnow accept spaces and trailing commas in their list values instead of refusing to start.- Fixed "Mark all as read" on the unread page, which marked entries from categories hidden from the global unread list.
- Fixed a category deletion check that could remove all of a user's categories.
- Fixed pagination in the Entries API: the total count is now correct when the requested offset is past the last entry.
- Fixed the
no_media_playeroption being ignored when creating a feed. - A feed proxy URL can now be cleared once it has been configured.
- Fixed
entry_sorting_ordervalidation on user modification, which returned a server error instead of a validation error for unsupported values. - Fixed the
fetch_via_proxycheckbox disappearing when the subscription page was re-rendered after an error. - Fixed the
remove_tablesrewrite rule reordering article content. - Fixed plain text
content_textandsummaryvalues from JSON Feed being mangled when they contained markup-like characters. - Fixed empty tags being sent to Raindrop when no tag was configured.
- Fixed overlapping article headings that wrap onto multiple lines.
- Fixed Atom language parsing to only consider namespace-qualified
xml:langattributes.
Dependencies
Updated several Go modules and GitHub Actions dependencies, including:
github.com/andybalholm/brotli1.2.2github.com/coreos/go-oidc/v33.20.0github.com/prometheus/client_golang1.24.0golang.org/x/crypto0.54.0golang.org/x/net0.57.0golang.org/x/text0.40.0
As always, thank you to all contributors who helped improve Miniflux in this release.
Breaking Changes
- Unix sockets now created with 0660 permissions; deployments must ensure the reverse‑proxy user shares a group with the Miniflux process.
Security Fixes
- Fixed information disclosure allowing any authenticated user to read other users' favicons via `GET /v1/icons/{iconID}`.
- Restricted Unix socket permissions from world‑writable (0777) to group‑restricted (0660).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]