File tree Expand file tree Collapse file tree 2 files changed +22
-3
lines changed
Expand file tree Collapse file tree 2 files changed +22
-3
lines changed Original file line number Diff line number Diff line change 3030
3131## Version 6
3232
33+ ### v6.10.4
34+
35+ Released on Dec 11th, 2025
36+
37+ #### Minor Reflected SSRF fix
38+
39+ We have been reported (CVE incomming) that a minor SSRF vulnerability was still present in Lychee.
40+ The patch from v6.6.13 did not fully mitigate the issue as an edge cases as not considered.
41+ The validation is done on the first URL, however if the URL is redirected, the redirection target was not validated against local network etc.
42+
43+ A big thanks to TableBasse, midfirewear, and petouha for reporting this vulnerability to us.
44+
45+ #### Most notable changes
46+
47+ * Mitigate small SSRF by @ildyria in https://github.com/LycheeOrg/Lychee/pull/3861
48+
49+
50+ ** Full Changelog** : https://github.com/LycheeOrg/Lychee/compare/v6.10.3...v6.10.4
51+
3352### v6.10.3
3453
3554Released on Dec 4th, 2025
Original file line number Diff line number Diff line change 1010 >NEW</span
1111 >
1212 <a
13- href =" https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.3 "
14- class =" text-slate-200 hover:underline dark:text-slate-200 font-medium" >Lychee 6.10.3 is now available! »</a
13+ href =" https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.4 "
14+ class =" text-slate-200 hover:underline dark:text-slate-200 font-medium" >Lychee 6.10.4 is now available! »</a
1515 >
1616 <!-- <a
17- href="https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.3 "
17+ href="https://github.com/LycheeOrg/Lychee/releases/tag/v6.10.4 "
1818 class="text-slate-200 hover:underline dark:text-slate-200 font-medium"><span class="text-red-500 font-bold">CVSS 7.5 in Lychee [6.6.6 to 6.6.9], update as soon as possible!</span> Lychee v6.9.1 is now available! »</a
1919 > -->
2020 <a
You can’t perform that action at this time.
0 commit comments