This release includes 1 security fix for security teams reviewing exposed deployments.
Published 16h
Dashboards & Home Pages
✓ No known CVEs patched
This release patches 1 known CVE
Topics
algernon
build-less
cross-platform
fasthttp
go
http3
+14 more
live-reload
local-llm
lua
mysql
npm-less
ollama
pongo2
postgresql
quic
react19
redis
server-sent-events
sqlite
tls13
Affected surfaces
rce_ssrf
Summary
AI summaryFixed security issue with crafted path segments such as %2fadmin/.
Full changelog
- Fix empty responses when served by reverse proxies, ref #175, thanks @Archie3d.
- Fix a security issues related to paths like
/%2fadmin/, thanks @arpitjain099. - Update dependencies.
- Update documentation.
Security Fixes
- Fixed security issue with crafted path segments such as `%2fadmin/`.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Algernon
Small self-contained pure-Go web server with Lua, Markdown, HTTP/2, QUIC, Redis and PostgreSQL support.
Related context
Related tools
Beta — feedback welcome: [email protected]