Skip to content

ntfy

Alerting & Incidents

A simple HTTP-based pub‑sub service for sending push notifications to phones or desktops without signing up or paying fees

Go Latest v2.26.3 · 6d ago Security brief →

Features

  • Send push notifications via plain HTTP PUT/POST requests
  • Free public instance at ntfy.sh with no registration required
  • Open‑source client apps for Android and iOS (Google Play, F‑Droid, App Store)
  • Self‑hostable server to keep data private

Recent releases

View all 15 releases →
Config change
v2.26.3 New feature
Auth

abuse ban‑feed

Upgrade now
v2.26.0 Security relevant

Template timeout security fix

Upgrade now
v2.25.0 New feature
Auth

Password reset + verification rewrite

Review required
v2.23.0 Security relevant
Dependencies Auth

Safe image preview restriction

v2.22.0 Security relevant
Security fixes
  • SSRF vulnerability in web push endpoint allow-list regex (GHSA-w9hq-5jg7-q4j7)
Notable features
  • Access tokens can now be set to never expire in web app
  • Fixed web app crash on account page for tokens without last access time
Full changelog

Bug fixes + maintenance:

  • Tighten web push endpoint allow-list regex to prevent SSRF via unanchored pattern matching (GHSA-w9hq-5jg7-q4j7, thanks to @MightyNawaf for reporting)
  • Fix web app not allowing access tokens to be changed to never expire (#1693/#1694, thanks to @lastsamurai26 for reporting and to @ShipItAndPray for fixing)
  • Fix web app crashing on account page for tokens without a last access time (#1651, #1684, thanks to @Pulsar7 and @rzhli for reporting)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
32,007
Forks
1,419
Languages
Go JavaScript Makefile

Install & Platforms

Mobile
Android IOS

Tracked by

1 person tracking

People also track

Beta — feedback welcome: [email protected]