Skip to content

Commit e16a18b

Browse files
committed
update version 6.10.4
1 parent 3cd684d commit e16a18b

File tree

2 files changed

+22
-3
lines changed

2 files changed

+22
-3
lines changed

docs/releases.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,25 @@
3030

3131
## Version 6
3232

33+
### v6.10.4
34+
35+
Released on Dec 11th, 2025
36+
37+
#### Minor Reflected SSRF fix
38+
39+
We have been reported (CVE incomming) that a minor SSRF vulnerability was still present in Lychee.
40+
The patch from v6.6.13 did not fully mitigate the issue as an edge cases as not considered.
41+
The validation is done on the first URL, however if the URL is redirected, the redirection target was not validated against local network etc.
42+
43+
A big thanks to TableBasse, midfirewear, and petouha for reporting this vulnerability to us.
44+
45+
#### Most notable changes
46+
47+
* Mitigate small SSRF by @ildyria in https://github.com/LycheeOrg/Lychee/pull/3861
48+
49+
50+
**Full Changelog**: https://github.com/LycheeOrg/Lychee/compare/v6.10.3...v6.10.4
51+
3352
### v6.10.3
3453

3554
Released on Dec 4th, 2025

src/components/widgets/Announcement.astro

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,11 +10,11 @@
1010
>NEW</span
1111
>
1212
<a
13-
href="https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.3"
14-
class="text-slate-200 hover:underline dark:text-slate-200 font-medium">Lychee 6.10.3 is now available! »</a
13+
href="https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.4"
14+
class="text-slate-200 hover:underline dark:text-slate-200 font-medium">Lychee 6.10.4 is now available! »</a
1515
>
1616
<!-- <a
17-
href="https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.3"
17+
href="https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.4"
1818
class="text-slate-200 hover:underline dark:text-slate-200 font-medium"><span class="text-red-500 font-bold">CVSS 7.5 in Lychee [6.6.6 to 6.6.9], update as soon as possible!</span> Lychee v6.9.1 is now available! »</a
1919
> -->
2020
<a

0 commit comments

Comments
 (0)