Skip to content

Commit b311337

Browse files
authored
Update version 6.10.4 (#251)
1 parent 3cd684d commit b311337

File tree

3 files changed

+116
-105
lines changed

3 files changed

+116
-105
lines changed

docs/releases.md

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,27 @@
3030

3131
## Version 6
3232

33+
### v6.10.4
34+
35+
Released on Dec 11th, 2025
36+
37+
#### Minor Reflected SSRF fix
38+
39+
We have been reported (CVE incoming) that a minor SSRF vulnerability was still present in Lychee.
40+
The patch from v6.6.13 did not fully mitigate the issue because an edge case had not been considered.
41+
Validation is done on the initial URL; however, if the URL is redirected, the redirection target was not validated against local network etc.
42+
To fix this, we added a new _expert_ configuration option in the admin section which disables following redirects when importing from URL.
43+
44+
45+
A big thanks to TableBasse, midfirewear, and petouha for reporting this vulnerability to us.
46+
47+
#### Most notable changes
48+
49+
* Mitigate small SSRF by @ildyria in https://github.com/LycheeOrg/Lychee/pull/3861
50+
51+
52+
**Full Changelog**: https://github.com/LycheeOrg/Lychee/compare/v6.10.3...v6.10.4
53+
3354
### v6.10.3
3455

3556
Released on Dec 4th, 2025

0 commit comments

Comments
 (0)