This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThis release patches an LDAP access key filter injection vulnerability and addresses multiple Azure‑related handling bugs.
Why it matters: The LDAP fix (severity 90) prevents authentication bypass; all environments using LDAP must upgrade immediately to block the injection flaw.
Summary
AI summaryAdd configurable default ETag for files without metadata, a chart sidecar with versioning directory support.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes LDAP access key filter injection vulnerability. Fixes LDAP access key filter injection vulnerability. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds chart sidecar and versioning directory support. Adds chart sidecar and versioning directory support. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds configurable default ETag for files without metadata. Adds configurable default ETag for files without metadata. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Updates Fiber dependency to v3.4.0. Updates Fiber dependency to v3.4.0. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes Azure ETag quote bytes handling issue. Fixes Azure ETag quote bytes handling issue. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes Azure multipart ETag quoting problem. Fixes Azure multipart ETag quoting problem. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes copy-source parsing mismatch that could bypass path validation. Fixes copy-source parsing mismatch that could bypass path validation. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes nil pointer panic in s3proxy ListMultipartUploads and ListParts. Fixes nil pointer panic in s3proxy ListMultipartUploads and ListParts. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Omits null version ID for suspended buckets. Omits null version ID for suspended buckets. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Refactor | Low |
Removes go report card integration. Removes go report card integration. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Changelog
- 1335bb4b8130edd85967701a806c3f0140f6056e Remove go report card
- 2ca9a23b5d4de46f044aad8897259a405a4960a4 chore(deps): bump the dev-dependencies group across 1 directory with 21 updates
- 03f02a9393d292be0046214385b4c7274a873251 chore(deps): bump the dev-dependencies group with 14 updates
- 26319f50b79045d82a477f6d72604af8f45be16d chore(deps): bump the dev-dependencies group with 15 updates
- 568d4a25ccc60b4283c52d20be5e416976521393 feat: add chart sidecar and versioning directory support
- 9db2c9c702aba324f8d44f2fc269e135e45f3cf4 feat: add configurable default ETag for files without metadata
- 05cfa0fffa5433851ed849a2abd68cdf6e6eaba4 fix azure etag quote bytes
- efa7e7739a583b7f5c67d95444fcd843e468e859 fix azure multipart etag quoting
- 9ac52cd5c7fe210db5d2323f7cff65d3c76c9f6e fix: LDAP access key filter injection
- a37b655ab73e859a01e8b50557c0c23de41b1fec fix: add section for goreleaser deb/rpm
- 67aaa80d999f225724c90f8f9f562e4163075580 fix: copy-source parsing mismatch that could bypass path validation
- 8a3dbcf97d996ea4955426e6b8a76eb96d2cd92a fix: omit null version id for suspended buckets
- 1a92f39b469755d19b04e8a11082ad03f306b9ea fix: prevent nil pointer panic in s3proxy ListMultipartUploads and ListParts
- 2f6b984b07cc280216aaa77e81d6e91643a3fbf9 fix: update Fiber to
v3.4.0 - dbc9bb1b088fb7a13d64b6254dcb47eabd93f997 fix: update example config with recent options
- 12f22838e25e88a2dd3760aa0f5be884ed34536e make azure multipart part etags quoted and consistent
- 40cbe85612f2a3fba68c00a2177706a053c74326 test(azure): widen multipart test parts above min size; tighten isQuotedEtag
Security Fixes
- Fix LDAP access key filter injection
- Fix copy-source parsing mismatch that could bypass path validation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]