Skip to content

Algernon

v1.17.11 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

algernon build-less cross-platform fasthttp go http3
+14 more
live-reload local-llm lua mysql npm-less ollama pongo2 postgresql quic react19 redis server-sent-events sqlite tls13

Affected surfaces

rce_ssrf

Summary

AI summary

Fixed security issue with crafted path segments such as %2fadmin/.

Full changelog
  • Fix empty responses when served by reverse proxies, ref #175, thanks @Archie3d.
  • Fix a security issues related to paths like /%2fadmin/, thanks @arpitjain099.
  • Update dependencies.
  • Update documentation.

Security Fixes

  • Fixed security issue with crafted path segments such as `%2fadmin/`.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Algernon

Get notified when new releases ship.

Sign up free

About Algernon

Small self-contained pure-Go web server with Lua, Markdown, HTTP/2, QUIC, Redis and PostgreSQL support.

All releases →

Related context

Beta — feedback welcome: [email protected]